Otomatisasi Penanganan Insiden Siber Menggunakan Shuffle melalui Implementasi Playbook

Sinambela, Riyanda Cavin (2026) Otomatisasi Penanganan Insiden Siber Menggunakan Shuffle melalui Implementasi Playbook. Other thesis, InstitutTeknologi Sepuluh Nopember.

[thumbnail of 5025221100-Undergraduate_Thesis.pdf] Text
5025221100-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (6MB)

Abstract

Peningkatan volume dan kompleksitas serangan siber menuntut respons insiden yang cepat dan konsisten, sementara penanganan insiden secara manual oleh Security Operations Center (SOC) Analyst memerlukan waktu yang lama dan rentan terhadap keterlambatan, terutama di luar jam operasional. Penelitian ini bertujuan merancang dan mengimplementasikan sistem otomatisasi penanganan insiden siber berbasis Security Orchestration, Automation, and Response (SOAR) untuk mempercepat proses deteksi dan respons terhadap berbagai jenis ancaman. Sistem dibangun dengan mengintegrasikan Wazuh sebagai Security Information and Event Management (SIEM), Suricata sebagai Intrusion Detection System (IDS), Shuffle sebagai platform SOAR, VirusTotal sebagai sumber threat intelligence, DFIR-IRIS sebagai platform manajemen insiden, dan Telegram sebagai notification channel. Sebanyak empat belas playbook (PB-A hingga PB-N) dirancang untuk menangani berbagai jenis insiden. Tiga playbook (PB-A, PB-B, dan PB-C) dievaluasi secara fungsional menggunakan log dari infrastruktur institusi, yaitu serangan WAF F5 BigIP, pemblokiran IP PaloAlto, dan pelanggaran kepatuhan Security Configuration Assessment (SCA), sedangkan sebelas playbook lainnya (PB-D hingga PB-N) diuji melalui tujuh belas skenario serangan yang mencakup honeypot, web shell, defacement judi online, malware, port scanning, privilege escalation, SSH brute force, reverse shell, web scanning, directory traversal, log tampering, komunikasi command and control, dan DNS tunneling. Setiap playbook dipetakan terhadap MITRE ATT&CK Framework dan diuji sebanyak tiga kali untuk mengukur Mean Time To Detect (MTTD) dan Mean Time To Respond (MTTR). Hasil pengujian menunjukkan seluruh skenario berhasil dieksekusi dan ditangani secara otomatis dengan rata-rata MTTD 1,9 detik dan MTTR 38,7 detik, dengan rentang MTTD 0 hingga 9 detik dan MTTR 18,3 hingga 108 detik. Penerapan pendekatan defense in depth pada deteksi web shell yang menggabungkan File Integrity Monitoring dan auditd terbukti meningkatkan ketahanan deteksi dengan tetap mempertahankan MTTR yang rendah. Hasil ini menunjukkan sistem mampu mendeteksi ancaman secara real-time dan merespons insiden secara otomatis jauh lebih cepat dibandingkan respons manual, sehingga meningkatkan efektivitas operasional penanganan insiden siber.
==================================================================================================================================
The increasing volume and complexity of cyber attacks demand fast and consistent incident response, while manual incident handling by Security Operations Center (SOC) analysts is time-consuming and prone to delays, particularly outside operational hours. This study aims to design and implement a cyber incident response automation system based on Security Orchestration, Automation, and Response (SOAR) to accelerate the detection and response process against various types of threats. The system was built by integrating Wazuh as a Security Information and Event Management (SIEM) system, Suricata as an Intrusion Detection System (IDS), Shuffle as the SOAR platform, VirusTotal as a threat intelligence source, DFIR-IRIS as an incident management platform, and Telegram as a notification channel. Fourteen playbooks (PB-A to PB-N) were designed to handle various types of incidents. Three playbooks (PB-A, PB-B, and PB-C) were functionally evaluated using historical logs from the institution's infrastructure, namely F5 BigIP WAF attacks, PaloAlto IP blocking, and SCA compliance violations, while the remaining eleven playbooks (PB-D to PB-N) were tested through seventeen attack scenarios covering honeypot intrusion, web shell, online gambling defacement, malware, port scanning, privilege escalation, SSH brute force, reverse shell, web scanning, directory traversal, log tampering, command and control communication, and DNS tunneling. Each playbook was mapped against the MITRE ATT&CK framework and tested three times to measure Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR). The testing results show that all scenarios were successfully executed and handled automatically, with an average MTTD of 1.9 seconds and MTTR of 38.7 seconds, with MTTD ranging from 0 to 9 seconds and MTTR from 18.3 to 108 seconds. The application of a defense in depth approach to web shell detection, combining File Integrity Monitoring and auditd, proved to improve detection resilience while maintaining a low MTTR. These results demonstrate that the system is capable of detecting threats in near real-time and responding to incidents automatically far faster than manual response, thereby improving the operational effectiveness of cyber incident handling.

Item Type: Thesis (Other)
Uncontrolled Keywords: DFIR-IRIS, MTTD, MTTR, Shuffle, SIEM, SOAR, VirusTotal, Wazuh
Subjects: T Technology > TK Electrical engineering. Electronics Nuclear engineering > TK5105 Data Transmission Systems
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis
Depositing User: Riyanda Cavin Sinambela
Date Deposited: 24 Jul 2026 15:44
Last Modified: 24 Jul 2026 15:47
URI: http://repository.its.ac.id/id/eprint/138138

Actions (login required)

View Item View Item