Deteksi dan Mitigasi Serangan Aplikasi Web Menggunakan Suricata IPS, Wazuh SIEM, dan Firewall
DOI:
https://doi.org/10.35746/jtim.v8i4.1146Keywords:
Suricata IPS, Wazuh SIEM, Firewall, SQLi, Stored XSSAbstract
Web applications have become a primary platform for delivering digital services but face security threats, particularly SQL Injection (SQLi) and Cross-Site Scripting (XSS). The limitations of conventional firewalls in detecting application-layer attacks highlight the need for automated detection and mitigation. This study evaluates an integrated security framework based on Suricata Intrusion Prevention System (IPS), Wazuh Security Information and Event Management (SIEM), and a firewall in a cloud environment. The Network Development Life Cycle (NDLC) method was implemented on Ubuntu Server and Damn Vulnerable Web Application (DVWA). Four attack scenarios were tested: Error-Based SQLi, Union-Based SQLi, Authentication Bypass SQLi, and XSS. Results showed that three scenarios (75%) were successfully detected, responded to, and blocked through Active Response. Suricata recorded seven detection events for Error-Based SQLi and four alerts each for Union-Based SQLi and XSS. Wazuh recorded alerts and executed Active Response for these scenarios, while the firewall blocked 281, 215, and 73 packets, respectively. Authentication Bypass SQLi generated 46 Suricata events and 15 Wazuh alerts but did not trigger Active Response or firewall blocking because SQLMap did not identify the username parameter as vulnerable. These findings demonstrate that integrating Suricata IPS, Wazuh SIEM, and a firewall supports auto-mated detection, analysis, and mitigation of web attacks through a defense-in-depth approach.
Downloads
References
S. S. Nasim, P. Pranav, and S. Dutta, “A systematic literature review on intrusion detection techniqu- es in cloud computing,” Discover Computing, vol. 28, no. 1, pp. 2–35, 2025. https://doi.org/10.1007/s10791-025-09641-y.
M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion de- tection: Approaches, datasets, and comparative study,” Journal of Information Security and Applications, vol. 50, no. 102419, pp. 1–20, 2020. https://doi.org/10.1016/j.jisa.2019.102419.
C. Moharir, S. K. Lingishetty, and A. Kamboj, “Securing web applications against sql injection and xss attacks,” Journal of Information Security and Applications, vol. 14, no. 5, pp. 203–208, 2025. https://doi.org/10.51583/IJLTEMAS.2025.140500025.
S. E. Prasetyo, H. Haeruddin, and K. Ariesryo, “Sistem keamanan website dari serangan denial of service, sql injection, cross site scripting menggunakan web application firewall,” Antivirus: Jurnal Ilmiah Teknik Informatika, vol. 18, no. 1, pp. 27–36, 2024. https://doi.org/10.35457/antivirus.v18i1.3339.
C. Chamberland, “2024 annual wordpress vulnerability and threat report by wordfence,” Apr. 2025. Accessed: Sep. 18, 2026. [Online]. Available: https://www.wordfence.com/wp-content/uploads/2025/04/2024-Annual-WordPress-Security-Report-by-Wordfence.pdf.
A. Paul, V. Sharma, and O. Olukoya, “Sql injection attack: Detection, prioritization & prevention,” Journal of Information Security and Applications, vol. 85, no. 103871, pp. 1–21, 2024. https://doi.org/10.1016/j.jisa.2024.103871.
G. Deshmukh, R. Kamble, and P. S. Solanki, “Protection of network devices and data security using firewall: A literature survey,” International Journal of Computer Sciences and Engineering, vol. 9, no. 11, pp. 39–44, 2021. https://doi.org/10.26438/ijcse/v9i11.3944.
P. Senthil, B. P. Kavin, S. R. Srividhya, V. Ramachandran, C. Kavitha, and W. C. Lai, “Performance evaluation of stateful firewall-enabled sdn with flow-based scheduling for distributed controllers,” Electronics (Switzerland), vol. 11, no. 19, pp. 2–20, 2022. https://doi.org/10.3390/electronics11193000.
E. Kristi, A. Tobing, R. E. Septya, and Y. Servanda, “Comparative analysis of network security: Fire- wall, ids, and ai-based defense against ddos attacks,” Journal of Artificial Intelligence and Engineering Applications (JAIEA), vol. 4, no. 3, pp. 1818–1822, 2025. https://doi.org/10.59934/jaiea.v4i3.1026.
E. Stephani, F. Nova, E. Asri, and N. Fitri, “Implementasi dan analisa keamanan jaringan ids (intrusion de- tection system) menggunakan suricata pada web server,” JITSI: Jurnal Ilmiah Teknologi Sistem Informasi, vol. 1, no. 2, pp. 67–74, 2020. https://doi.org/10.62527/jitsi.1.2.10.
F. T. Anugrah et al., “Implementasi intrusion prevention system (ips) menggunakan suricata untuk serangan sql injection,” Techné: Jurnal Ilmiah Elektroteknika, vol. 21, no. 2, pp. 199–210, 2022. https://doi.org/10.31358/techne.v21i2.320.
H. Asad and I. Gashi, “Dynamical analysis of diversity in rule-based open source network intrusion dete- ction systems,” Empirical Software Engineering, vol. 27, no. 1, pp. 2–30, 2022. https://doi.org/10.1007/s10664-021-10046-w.
M. A. Mishra, “Integration of siem for real-time threat detection,” International Journal of Engineering Development and Research (IJEDR), vol. 14, no. 1, pp. 512–520, 2026. https://rjwave.org/ijedr/papers/IJEDR2601447.pdf.
A. Alanda, H. A. Mooduto, and R. Hadi, “Real-time defense against cyber threats: Analyzing wazuh’s effectiveness in server monitoring,” JITCE, vol. 7, no. 2, pp. 56–62, 2023. https://doi.org/10.25077/jitce.7.2.56-62.2023.
H. A. Damanik and M. Anggraeni, “Sistem deteksi intrusi hybrid dan mitigasi kerentanan infrastruktur jaringan menggunakan teknik active response (xdr) wazuh dan suricata,” Jurnal Pekommas, vol. 9, no. 2, pp. 309–322, 2024. https://doi.org/10.56873/jpkm.v9i2.5829.
R. S. Wiandani, M. Tahir, I. A. Dyransyha, and R. Ummah, “Identifikasi serangan sql injection berban- tuan aplikasi pengujian keamanan web dvwa (damn vulnerable web application),” Digital Transformation Technology (Digitech), vol. 5, no. 1, pp. 375–382, 2025. https://doi.org/10.47709/digitech.v5i1.5922.
H. Setiawan, W. Sulistyo, F. T. Informasi, and U. K. S. Wacana, “Siem (security information event management) model for malware attack detection using suricata and evebox,” International Journal of Engineering Technology and Natural Sciences (IJETS), vol. 5, no. 2, pp. 138–147, 2023. https://doi.org/10.46923/ijets.v5i2.241
R. Rodianto, I. Idham, Y. Yuliadi, M. T. A. Zaen, and W. Ramadhan, “Penerapan network development life cycle (ndlc) dalam pengembangan jaringan komputer pada badan pengelolaan keuangan dan aset daerah (bpkad) provinsi ntb,” Jurnal Ilmiah FIFO, vol. 14, no. 1, pp. 35–46, 2022. http://dx.doi.org/10.22441/fifo.2022.v14i1.004.
M. Djamalyanto, L. Widyawati, and I. P. Hariyadi, “Implementasi security information and event ma- nagement untuk mencegah serangan deface pada server terintegrasi telegram,” Melek IT: Information Technology Journal, vol. 11, no. 1, pp. 31–42, 2025. https://doi.org/10.30742/melekitjournal.v11i1.398.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ardiansyah Ardiansyah, Raisul Azhar, Lilik Widyawati

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.









