IMPLEMENTASI SNORT INLINE MODE DAN ELK STACK UNTUK DETEKSI DAN MITIGASI SERANGAN PADA INFRASTRUKTUR LAYANAN DIGITAL PENDIDIKAN BERBASIS DOCKER

Authors

  • Vian Maulana Fatah Institut Teknologi dan Bisnis Asia Malang
  • Achmad Noercholis Institut Teknologi dan Bisnis Asia Malang
  • Fransiska Sisilia Mukti Institut Teknologi dan Bisnis Asia Malang

DOI:

https://doi.org/10.23969/jp.v11i02.54016

Keywords:

Snort Inline Mode, ELK Stack, Docker, Digital Education Services Infrastructure, Intrusion Prevention System

Abstract

The rapid development of digital education services has increased educational institutions' dependence on information technology infrastructure. Various cyber threats such as brute force attacks, port scanning, ping sweep, and denial-of-service attacks can disrupt service availability and interfere with academic and administrative activities. Therefore, an effective security mechanism is required to detect and mitigate cyberattacks in real time. This study aims to implement a Snort Inline Mode-based Intrusion Prevention System integrated with the ELK Stack (Elasticsearch, Logstash, Kibana) within a Docker-based digital education services infrastructure environment. The research employed an experimental method by developing a containerized architecture consisting of attacker, digital education service server, Snort IPS, Filebeat, Logstash, Elasticsearch, and Kibana containers. Active mitigation was implemented using Netfilter Queue (NFQUEUE), enabling Snort to inspect and block malicious traffic before reaching the target server. Four attack scenarios were tested, including SSH Brute Force, ICMP Ping Sweep, TCP Port Scan, and TCP SYN Flood. The results indicate that the system successfully detected and mitigated all attack scenarios with a mitigation success rate of 100% and response times below one second. Furthermore, ELK Stack integration provided centralized and real-time security monitoring through Kibana dashboards, facilitating threat analysis and security management. The findings demonstrate that the combination of Snort Inline Mode and ELK Stack in a Docker environment can serve as an effective security solution to support the reliability, security, and availability of digital education services infrastructure

Downloads

Download data is not yet available.

References

Awal, H., & Gusman, A. P. (2023). IMPLEMENTASI INTRUSION DETECTION PREVENTION SYSTEM SEBAGAI SISTEM KEAMANAN JARINGAN KOMPUTER KEJAKSAAN NEGERI PARIAMAN MENGGUNKAN SNORT DAN IPTABLES BERBASIS LINUX. In Jurnal Sains Informatika Terapan (JSIT) E-ISSN (Vol. 2, Number 2). Bulan Juni.

Denanta Alviani, C., Setiawan Padi, A., & Puspitasari, N. (2024). SEMINAR NASIONAL AMIKOM SURAKARTA (SEMNASA) 2024 KEAMANAN SIBER DI MASA DEPAN : TANTANGAN DAN TEKNOLOGI YANG DIBUTUHKAN.

Mahendra, D., & Mukti, F. (2022). Sistem Deteksi dan Pengendalian Serangan Denial of Service pada Server Berbasis Snort dan Telegram-API Detection and Control System of Denial of Service Attack on Server Based on Snort and Telegram-API. In Agustus (Vol. 21, Number 3).

Ernawati, T., & Rachmat, F. F. F. (2021). Network Security with Cowrie Honeypot and Snort Inline-Mode as Intrusion Prevention System. Jurnal RESTI, 5(1), 180–186. https://doi.org/10.29207/resti.v5i1.2825

Hamzah, R. A., & Prihanto, A. (2025). Implementasi Cowrie Honeypot Dan Snort Inline-Mode Untuk Mendeteksi Serangan Brute-Force Dan Simulasi Deteksi Serangan Dos. Journal of Informatics and Computer Science, 07(2).

Intan Sabila, M., Tahir, M., Dwi Mardania, S., & Ilham Arifin, R. (2025). IMPLEMENTASI SNORT SEBAGAI IDS DALAM MENDETEKSI SERANGAN PORT SCANNING NMAP PADA SIMULASI JARINGAN VIRTUAL. In Jurnal Mahasiswa Teknik Informatika) (Vol. 9, Number 4).

Mukti, F. S., & Sukmawan, R. M. (2021). INTEGRATION OF LOW INTERACTION HONEYPOT AND ELK STACK AS ATTACK DETECTION SYSTEMS ON SERVERS. In Jurnal Penelitian Pos dan Informatika (Vol. 11, Number 1).

Pradipta, Y. W., & Asmunin. (2017). Implementasi Intrusion Prevention System (IPS) Mengggunakan IPTABLES Linux IMPLEMENTASI INTRUSION PREVENTION SYSTEM (IPS) MENGGUNAKAN SNORT DAN IP TABLES BERBASIS LINUX. www.snort.org.

Pradita, G., & Pramono, A. (2024). IMPLEMENTASI MONITORING KEAMANAN JARINGAN PADA SERVER UBUNTU MENGGUNAKAN SNORT INTRUSION DETECTION PREVENTION SYSTEM (IDPS) DAN TELEGRAM BOT SEBAGAI MEDIA NOTIFIKASI DI PT SS UTAMA. In Jurnal Mahasiswa Teknik Informatika (Vol. 8, Number 4).

Pratikno R, Trinata C, & Hertantyo G. (2025). KAJIAN+LITERATUR+ANALISIS+KEAMANAN+JARINGAN. Pendas : Jurnal Ilmiah Pendidikan Dasar, 20(2), 2477–2143.

Purba, W. W., & Efendi, R. (2020). Perancangan dan analisis sistem keamanan jaringan komputer menggunakan SNORT. AITI: Jurnal Teknologi Informasi, 17(2), 143–158.

Ramadhan, A., Kom, S., Kom, M., & Rafif Hadi Kusmawan, M. (2026). Implementasi Cisco ISE (Identity Service Engine) sebagai Network Access Control (NAC) untuk Meningkatkan Keamanan Akses Jaringan pada Simulasi Infrastruktur TI Modern.

Robbani, F. D., Haryatmi, E., Riyadi, T. A., Supono, R. A., Kurniawan, A. B., & Rosdiana. (2025). Implementation of an Intrusion Detection System Using Snort and Log Visualization Using ELK Stack. International Journal of Engineering, Science and Information Technology, 5(3), 220–228. https://doi.org/10.52088/ijesty.v5i3.901

Santi, N., & Mulyanto, Y. (2024). ANALISIS KELAYAKAN JARINGAN KOMPUTER MENGGUNAKAN ALAT SNIFFING DAN INTRUSION DETECTION SYSTEM (IDS) (STUDI KASUS : FITRIA_HOTSPOT). In Jurnal Mahasiswa Teknik Informatika (Vol. 8, Number 4).

Setiyawan, A., Pinandito, A., & Purnomo, W. (2023). Pengembangan Sistem Informasi Log Management Server Monitoring Menggunakan ELK (Elastic Search, Logstash dan Kibana) Stack pada Aplikasi Padichain di PT. Bank Rakyat Indonesia (Vol. 7, Number 5). http://j-ptiik.ub.ac.id

Sisilia Mukti, F., Arbiyanto Sulistyo, D., & ASIA Malang, S. (2019). ANALISIS PENEMPATAN ACCESS POINT PADA JARINGAN WIRELESS LAN STMIK ASIA MALANG MENGGUNAKAN ONE SLOPE MODEL. Jurnal Ilmiah Teknologi Informasi Asia, 13(1).

Sisilia Mukti, F., Dani Prasetyo Adi, P., Arman Prasetya, D., Sihombing, V., Rahanra, N., Yuliawan, K., & Simatupang, J. (2021). Integrating Cost-231 Multiwall Propagation and Adaptive Data Rate Method for Access Point Placement Recommendation. In IJACSA) International Journal of Advanced Computer Science and Applications (Vol. 12, Number 4). https://doi.org/10.14569/IJACSA.2021.0120494

Suci Sekar Sari, & Agus Tedyyana. (2024). Analisis Efektivitas Rule Snort dalam Mendeteksi Serangan Jaringan. Repeater : Publikasi Teknik Informatika Dan Jaringan, 2(4), 01–15. https://doi.org/10.62951/repeater.v2i4.194

Susdyastama Putra, Y., Indriastuti, M. T., & Mukti, S. (2020). OPTIMALISASI NILAI THROUGHPUT JARINGAN LABORATORIUM MENGGUNAKAN METODE HIERARCHICAL TOKEN BUCKET (STUDI KASUS: STMIK ASIA MALANG). In Jurnal Ilmiah NERO (Vol. 5, Number 2).

Wulandari, T., Yudisthira, Y. F., P.H, K. C., Wibowo, M. A., & Andrew, C. (2025). Algoritma LightGBM untuk Deteksi Aktivitas Cyber Espionage Melalui Dataset Serangan Siber. JUSIFOR : Jurnal Sistem Informasi Dan Informatika, 4(2), 213–219. https://doi.org/10.70609/jusifor.v4i2.8489

Yudhistira, A., & Fitrisia, Y. (2023). MONITORING LOG SERVER DENGAN ELASTICSEARCH, LOGSTASH DAN KIBANA (ELK). Rabit : Jurnal Teknologi Dan Sistem Informasi Univrab, 8(1), 124–134. https://doi.org/10.36341/rabit.v8i1.2975

Downloads

Published

2026-07-09