Rancang Bangun Dan Evaluasi Awal Aplikasi Early Warning Serangan Pada Web Server Berbasis Dual-Intrusion Detection System
DOI:
https://doi.org/10.36312/38d3wq50Abstract
Peningkatan insiden kebocoran data pribadi menuntut mekanisme keamanan web server yang tidak hanya bersifat reaktif, tetapi juga mampu memberikan peringatan dini sebelum serangan berkembang menjadi insiden yang lebih luas. Penelitian ini bertujuan merancang dan mengevaluasi awal aplikasi Early Warning System berbasis dual-Intrusion Detection System yang mengintegrasikan Suricata dan Snort dengan Log Analyzer berbasis Python, notifikasi Telegram, basis data MySQL, dan dashboard Flask. Pendekatan penelitian menggunakan Design Science Research melalui tahapan identifikasi masalah, perumusan tujuan solusi, desain dan pengembangan artefak, demonstrasi, evaluasi, serta komunikasi hasil. Evaluasi dilakukan pada lingkungan virtual terkontrol menggunakan simulasi SQL Injection, Brute Force, dan Port Scanning terhadap web server uji yang memuat data pribadi sintetis. Hasil awal pada 180 paket/skenario serangan simulatif menunjukkan bahwa sistem terintegrasi mampu menghasilkan Detection Rate 100%, False Positive Rate 0%, dan rata-rata Time-to-Detect 2 detik. Namun, hasil tersebut ditafsirkan secara terbatas karena belum merepresentasikan trafik produksi kompleks, serangan evasive, maupun uji beban skala besar. Kontribusi utama penelitian ini adalah rancangan arsitektur EWS ringan yang menggabungkan normalisasi log, filtering severity, deduplikasi, dan korelasi alert lintas-IDS untuk menghasilkan informasi yang lebih dapat ditindaklanjuti oleh administrator. Penelitian ini memperlihatkan potensi penerapan EWS berbasis open-source untuk mendukung kewajiban perlindungan data pribadi, dengan kebutuhan validasi lanjutan melalui eksperimen komparatif terhadap Snort saja, Suricata saja, dual-IDS tanpa korelasi, dan dual-IDS dengan Log Analyzer.
The rising incidence of personal data breaches necessitates web server security mechanisms that are not merely reactive but capable of providing early warnings before an attack escalates into a widespread incident. This study aims to design and conduct a preliminary evaluation of an Early Warning System (EWS) based on a dual-Intrusion Detection System (IDS) architecture, integrating Suricata and Snort with a Python-based Log Analyzer, Telegram notifications, a MySQL database, and a Flask dashboard. The research employs the Design Science Research methodology, encompassing problem identification, solution objective formulation, artifact design and development, demonstration, evaluation, and communication of results. Evaluation was conducted in a controlled virtual environment using simulated SQL Injection, Brute Force, and Port Scanning attacks against a test web server containing synthetic personal data. Preliminary results from 180 simulated attack packets/scenarios indicate that the integrated system achieved a 100% detection rate, a 0% false positive rate, and an average time-to-detect of 2 seconds. However, these results are interpreted with limitations, as they do not yet represent complex production traffic, evasive attacks, or large-scale load testing. The study's primary contribution is the design of a lightweight EWS architecture that combines log normalization, severity filtering, deduplication, and cross-IDS alert correlation to generate information that is more actionable for administrators. This research demonstrates the potential of implementing an open-source-based EWS to support personal data protection obligations, while highlighting the need for further validation through comparative experiments involving Snort-only, Suricata-only, dual-IDS without correlation, and dual-IDS with the Log Analyzer configurations.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Rizky andika Putra, Ahmaddul Hadi

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with Journal of Authentic Research agree to the following terms:
- For all articles published in Journal of Authentic Research, copyright is retained by the authors. Authors give permission to the publisher to announce the work with conditions. When the manuscript is accepted for publication, the authors agrees to implement a non-exclusive transfer of publishing rights to the journals.
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.