Implementasi Wazuh Custom Decoder dan Rules untuk Deteksi Insiden Keamanan pada Aplikasi Berbasis Laravel dalam Arsitektur Kubernetes

Chrisnanta, Jericho Nathanael (2026) Implementasi Wazuh Custom Decoder dan Rules untuk Deteksi Insiden Keamanan pada Aplikasi Berbasis Laravel dalam Arsitektur Kubernetes. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5025221001-Undergraduate_Thesis.pdf] Text
5025221001-Undergraduate_Thesis.pdf
Restricted to Repository staff only

Download (11MB)

Abstract

Kubernetes banyak digunakan sebagai fondasi arsitektur cloud-native karena kemampuannya dalam mekanisme replikasi pod serta mendukung penskalaan yang fleksibel. Namun, log aplikasi pada Kubernetes tersebar di setiap pod-nya dan bersifat volatile sehingga menyulitkan analisis insiden secara terpusat. Penelitian ini merancang pipeline logging terpusat untuk aplikasi Laravel yang berjalan di lingkungan Kubernetes dengan memanfaatkan Fluent Bit sebagai log collector, serta Wazuh sebagai platform SIEM (Security Information and Event Management) untuk analisis log dan alerting. Pipeline ini menekankan normalisasi dan evaluasi log melalui konfigurasi custom decoder dan custom rule, sehingga log mentah dapat ditransformasikan menjadi field terstruktur dan selanjutnya dianalisis untuk mengidentifikasi aktivitas yang memenuhi kriteria deteksi tertentu. Hasilnya, proses monitoring dan analisis log kejadian menjadi lebih sistematis, dibuktikan dengan keberhasilan sistem mendeteksi secara akurat berbagai skenario serangan seperti SQL Injection, Directory Traversal, Command Injection, Cross-Site Scripting (XSS), dan Web Enumeration. Meskipun demikian, pengujian performa membuktikan adanya trade-off performa. Implementasi Fluent Bit sendiri sangat efisien dan hanya menurunkan throughput sebesar 5,72 request/sekon, namun pengaktifan seluruh fitur deteksi dan integrasi alerting Wazuh memberikan beban komputasi yang memangkas kapasitas pemrosesan hingga 23,29 request/sekon dengan detection latency di kisaran 2,6 hingga 2,8 detik. Penelitian ini menyimpulkan bahwa efektivitas visibilitas keamanan dari pipeline logging terpusat harus diimbangi dengan strategi alokasi resource yang matang untuk menjaga stabilitas kinerja sistem.
===============================================================================================================================
Kubernetes is widely used as the foundation for cloud-native architectures due to its capabilities in pod replication mechanisms and support for flexible scaling. However, application logs in Kubernetes are scattered across individual pods and are volatile in nature, which complicates centralized incident analysis. This research designs a centralized logging pipeline for a Laravel application running in a Kubernetes environment by utilizing Fluent Bit as a log collector and Wazuh as a SIEM (Security Information and Event Management) platform for log analysis and alerting. This pipeline emphasizes log normalization and evaluation through the configuration of custom decoders and custom rules, enabling raw logs to be transformed into structured fields and subsequently analyzed to identify activities that meet specific detection criteria. As a result, the monitoring and incident log analysis processes become more systematic, evidenced by the system's success in accurately detecting various attack scenarios such as SQL Injection, Directory Traversal, Command Injection, Cross-Site Scripting (XSS), and Web Enumeration. Nevertheless, performance testing reveals a performance trade-off. The implementation of Fluent Bit alone is highly efficient, reducing throughput by only 5.72 requests/second; however, the activation of all detection features and Wazuh alerting integration imposes a heavy computational load that cuts processing capacity by up to 23.29 requests/second, with a detection latency ranging from 2.6 to 2.8 seconds. This study concludes that the effectiveness of security visibility provided by a centralized logging pipeline must be balanced with a well-planned resource allocation strategy to maintain system performance stability.

Item Type: Thesis (Other)
Uncontrolled Keywords: Custom Decoder, Custom Rules, Fluent Bit, Kubernetes, Laravel, Wazuh
Subjects: Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science)
T Technology > T Technology (General) > T58.5 Information technology. IT--Auditing
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis
Depositing User: Jericho Nathanael Chrisnanta
Date Deposited: 30 Jul 2026 03:02
Last Modified: 30 Jul 2026 03:02
URI: http://repository.its.ac.id/id/eprint/137647

Actions (login required)

View Item View Item