Centralized Rule Sharing Implementation in the Mata Elang Intrusion Detection System (IDS)
I Gede Gilang Dharma Suputra, Septia Ulfa Sunaringtyas · 2024
In 2022, the National Cyber Security Operations Center (Pusopkamsinas) of the National Cyber and Crypto Agency (BSSN) recorded 976,429,996 traffic anomalies, with MyloBotnet being the dominant threat. Although the number of anomalies decreased compared to the previous year, cyber threats continue to evolve, posing new risks to the confidentiality, integrity, and availability of systems. Intrusion Detection System (IDS) and Security Information and Event Management (SIEM) systems are crucial solutions for detecting and handling attacks. The Mata Elang system, developed by Politeknik Elektronika Surabaya, utilizes Snort IDS and Pulledpork for automated rule configuration. However, limitations arise during rule customization, especially when involving multiple sensors. This research aims to address this issue by developing a centralized rule sharing approach that enables efficient automated IDS rule configuration across various sensors. This approach reduces reliance on the community for rule updates and optimizes attack handling more quickly. The research employed the SDLC Waterfall methodology to design, implement, and test a centralized rule-sharing system. This system allows organizations using the Mata Elang IDS to streamline rule distribution across sensors, reducing manual tasks and enhancing response times during attacks. Functional and non-functional testing confirmed that the push-based mechanism successfully distributed rules across sensors, providing identical configurations, improving detection capabilities, and aligning with the project's goals of improving operational efficiency and mitigating cyber threats in real time.