Pengembangan Kolaborasi Sistem Deteksi Intrusi Jaringan Tersebar Berbasis Publish-Subcribe Dengan Menggunakan Metode Alert Correlation

Winarno, Idris (2008) Pengembangan Kolaborasi Sistem Deteksi Intrusi Jaringan Tersebar Berbasis Publish-Subcribe Dengan Menggunakan Metode Alert Correlation. Masters thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5106201008-Master_thesis.pdf] Text
5106201008-Master_thesis.pdf
Restricted to Repository staff only

Download (24MB)

Abstract

Saat ini, banyak sekali jenis serangan yang terjadi pada suatu jaringan komputer, misalnya scanning, worms, exploit, denial of service, dan lain-lain. Kebanyakan sistem deteksi intrusi memberikan laporan ke sistem berdasarkan aktivitas yang telah terjadi. Namun, sistem deteksi intrusi ini memiliki beberapa kelemahan; di antaranya adalah tidak semua jenis serangan dapat terdeteksi hanya oleh satu jenis sistem deteksi intrusi, sehingga dibutuhkan kolaborasi antar sistem deteksi intrusi yang berada pada host yang berbeda-beda. Kelemahan lainnya adalah alert yang dihasilkan oleh sistem deteksi intrusi tidak semuanya bersifat true positive, sehingga diperlukan alert correlation untuk mereduksi alert yang bersifat false positive. Dengan adanya mekanisme publish-subscribe, proses kolaborasi sistem deteksi intrusi dapat diimplementasikan; publisher yang memiliki sensor akan memberikan laporan ke message server, namun sebelum laporan tersebut dikirim, alert terlebih dahulu direduksi melalui mekanisme alert correlation. Setelah dilakukan proses alert correlation pada publisher, message server akan mengirimkan message ke subscriber. Hasil uji coba menunjukkan bahwa dengan menggunakan alert correlation, suatu skenario serangan dapat diidentifikasi, yang mana jika hanya menggunakan laporan dari sensor tunggal, skenario serangan tersebut tidak dapat dikenali. Penggunaan alert correlation juga dapat mereduksi alert yang bersifat false positive karena terdapat komponen verification. Melalui mekanisme publish-subscribe, subscriber dapat menyeleksi alert hasil korelasi yang diinginkan, seperti alert yang mempunyai prioritas tinggi maupun prioritas rendah.
===================================================================================================================================
There are various types of intrusions that may occur in computer networks, such as scanning, worms, exploits, and denial-of-service attacks. Most current intrusion detection systems provide reports to the system based on activities that have occurred. However, these intrusion detection systems still have several limitations; for instance, not all intrusions can be detected by a single type of intrusion detection system, thereby requiring collaboration among intrusion detection systems residing on different hosts. Another limitation is that not all alerts generated by intrusion detection systems are true positives, making alert correlation necessary to reduce false positive alerts that may appear. A publish-subscribe mechanism can be utilized to establish collaboration among intrusion detection systems, in which a publisher equipped with a sensor publishes its report to a message server. An alert correlation mechanism is performed to reduce the number of alerts prior to publication, and the final alerts are subsequently distributed by the message server to the alert subscribers. Experiments show that utilizing alert correlation can identify intrusion scenarios that would otherwise remain undetected if only a single sensor's report were used. Moreover, alert correlation reduces false positive alerts by incorporating a verification component. Through the publish-subscribe mechanism, subscribers can selectively filter the correlated alerts according to their needs, such as high- or low-priority alerts.

Item Type: Thesis (Masters)
Additional Information: RTIf 005.8 Win p
Uncontrolled Keywords: sistem deteksi intrusi, publish-subscribe, alert correlation, intrusion detection system, publish-subscribe, alert correlation.
Subjects: T Technology > TK Electrical engineering. Electronics Nuclear engineering > TK2861 Electric relays. Protective relays--Security measures.
Divisions: Faculty of Information Technology > Informatics Engineering > 55101-(S2) Master Thesis
Depositing User: magang .
Date Deposited: 18 Sep 2026 06:38
Last Modified: 18 Sep 2026 06:38
URI: http://repository.its.ac.id/id/eprint/144678

Actions (login required)

View Item View Item