The rapid development of digital education services has increased educational institutions' dependence on information technology infrastructure. Various cyber threats such as brute force attacks, port scanning, ping sweep, and denial-of-service attacks can disrupt service availability and interfere with academic and administrative activities. Therefore, an effective security mechanism is required to detect and mitigate cyberattacks in real time. This study aims to implement a Snort Inline Mode-based Intrusion Prevention System integrated with the ELK Stack (Elasticsearch, Logstash, Kibana) within a Docker-based digital education services infrastructure environment. The research employed an experimental method by developing a containerized architecture consisting of attacker, digital education service server, Snort IPS, Filebeat, Logstash, Elasticsearch, and Kibana containers. Active mitigation was implemented using Netfilter Queue (NFQUEUE), enabling Snort to inspect and block malicious traffic before reaching the target server. Four attack scenarios were tested, including SSH Brute Force, ICMP Ping Sweep, TCP Port Scan, and TCP SYN Flood. The results indicate that the system successfully detected and mitigated all attack scenarios with a mitigation success rate of 100% and response times below one second. Furthermore, ELK Stack integration provided centralized and real-time security monitoring through Kibana dashboards, facilitating threat analysis and security management. The findings demonstrate that the combination of Snort Inline Mode and ELK Stack in a Docker environment can serve as an effective security solution to support the reliability, security, and availability of digital education services infrastructure
Copyrights © 2026