Web servers are essential but vulnerable to network attacks such as SYN Flood and port scanning. This study designs and implements an incident detection system by integrating Wazuh, Snort (IDS), and Telegram notifications following the Security Policy Development Life Cycle. Snort functions as a network sensor generating alerts forwarded to Wazuh for centralized log management and correlation; critical alerts are pushed to administrators via a Telegram bot for real-time response. The experimental environment uses virtualized machines that host a Wazuh server, a Snort IDS, a web server, and an attacker node. Evaluation metrics include detection accuracy, false-negative rate, and notification response time under two attack scenarios: SYN Flood and port scanning. Results indicate detection accuracy of 41.34% and a false-negative rate of 58.6% for SYN Flood attacks, with Snort-to-Wazuh latency of 13.559 ms and Telegram delivery of 0.4 s. Port scanning was detected with 100% accuracy and 0% false-negative rate, recording Snort-to-Wazuh latency of 1.490 ms and Telegram delivery of 1.33 s. The integration enhances centralized visibility and accelerates administrator awareness, yet it exhibits limitations for high-volume DoS traffic due to log buffering and throughput constraints. Recommendations include increasing Wazuh agent buffer capacity, optimizing Snort rules, and deploying higher-capacity hardware to improve detection under heavy attack loads.
Copyrights © 2025