Implemetation of Snort IPS Using PfSense as Network Forensic in Smk XYZ
Saleh Dwiyatno, Widya Ayu Andriani, Ayu Purnama Sari, Sulistiyono · 2020
The rise of attack software that can be easily accessed from the internet, makes anyone who doesn't ability to hack can do it.SMK Negeri 2 Pandeglang has a server that is used as a learning for all students.This encourages vulnerability to e-learning server attacked using software from the internet.So that a security system can detect attacks and take preventive actions and can carry out an investigation.This study aims to prevent any attempt to attack, detect and take preventive action against the attacker to carry out an investigation of the attack's log.This research was conducted using survey methods.The study was conducted for four months from April 1, 2019 to July 31, 2019.The result of this research is a security system that can detect an attack attempt and block the attacker's IP Address and conduct investigations using network forensic.Based on the result of the study it can be concluded that by using Snort with IPS mode stored on PfSense can detect attack aimed at elearning servers and PfSense automatically takes preventive measures in the form of blocking of the attacker's IP Address.From the alert generated by Snort, investigative action can be taken using network forensics so that reporting if the effects of the attack are detrimental.