Integration of Heterogeneous IDS with SIEM for DDoS Attack Detection in Computer Networked Multi-Organizational Environments

Makki Maliki, Parman Sukarno, Aulia Arif Wardana · 2024

The increasing reliance on computer networks for business operations has led to a rise in Distributed Denial of Service (DDoS) attacks. These attacks pose significant threats to network security, economic stability, and organizational operations. Organizations connected through the same network are particularly vulnerable. In response to these growing threats, detection systems have been developed to integrate heterogeneous Intrusion Detection Systems (IDS) with Security Information and Event Management (SIEM) systems. This integration assists in the detection of DDoS attacks within multi-organizational environments. The system employs the Opensearch dashboard, providing a centralized and efficient interface for the Security Operations Center. System testing was conducted through coordinated DDoS attack simulations by three attackers over a duration of 7-8 minutes. The Snort IDS demonstrated an average detection rate of 95.4%, with an alert correlation mechanism efficiency of 84.6%. Among the IDS systems tested, Zeek IDS consumed the most resources, with an average CPU usage of 24.6% and memory usage of 86.5%. In contrast, the Wazuh Dashboard exhibited lower resource consumption, with an average CPU usage of 0.6% and memory usage of 5.2%.

Read the paper · More papers on PaperTik