Muhammad Kahfi Darmawan, . (2026) ANALISIS FRAMEWORK T-POT DAN SIEM SEBAGAI SISTEM DETEKSI INTRUSI SERTA NOTIFIKASI REAL-TIME MELALUI TELEGRAM. Skripsi thesis, Universitas Pembangunan Nasional Veteran Jakarta.
|
Text
ABSTRAK.pdf Download (162kB) |
|
|
Text
AWAL.pdf Download (5MB) |
|
|
Text
BAB I.pdf Restricted to Repository UPNVJ Only Download (179kB) |
|
|
Text
BAB II.pdf Restricted to Repository UPNVJ Only Download (1MB) |
|
|
Text
BAB III.pdf Restricted to Repository UPNVJ Only Download (890kB) |
|
|
Text
BAB IV.pdf Restricted to Repository UPNVJ Only Download (4MB) |
|
|
Text
BAB V.pdf Download (180kB) |
|
|
Text
DAFTAR PUSTAKA.pdf Download (189kB) |
|
|
Text
RIWAYAT HIDUP.pdf Restricted to Repository staff only Download (145kB) |
|
|
Text
LAMPIRAN.pdf Restricted to Repository UPNVJ Only Download (628kB) |
|
|
Text
HASIL PLAGIARISME.pdf Restricted to Repository staff only Download (39MB) |
|
|
Text
ARTIKEL KI.pdf Restricted to Repository staff only Download (743kB) |
Abstract
The increasing threat of cyber attacks against network infrastructure demands an intrusion detection system capable of responding rapidly and consistently. This research aims to build, implement, and evaluate an intrusion detection system based on the T-Pot framework integrated with Security Information and Event Management (SIEM) using Elastic Stack, along with a real-time notification mechanism through Telegram. The system utilizes three core T-Pot components — Cowrie as an SSH honeypot, Dionaea as a multi-protocol honeypot, and Suricata as an Intrusion Detection System (IDS) — connected to ElastAlert2 as a rule-based alerting engine. As an additional contribution, the malware_vt_checker.py script was developed to perform automated enrichment of malware samples using the VirusTotal API. System evaluation was conducted in two phases. Organic testing over 16 effective days captured 6,332,283 events from 28,224 unique IP addresses across 163 countries, including the detection of 1,062 malware samples with 198 unique hashes, of which 98.56% were classified as malicious by VirusTotal. Controlled testing was performed with 150 iterations across five scenarios: SSH brute force, port scanning, DDoS/SYN flood, malware upload with VirusTotal, and malware upload without VirusTotal. Metrics measured include Mean Time to Detect (MTTD) as an indicator of end-to-end notification speed and success rate as an indicator of notification consistency. Results show an overall average MTTD of 24.902 seconds with a 100% success rate across all iterations. Per scenario, the lowest MTTD was achieved by malware without VirusTotal (15.067 seconds), followed by brute force (18.786 seconds), port scanning (22.769 seconds), and DDoS (28.703 seconds). The malware scenario with VirusTotal yielded an MTTD of 39.185 seconds due to external API enrichment overhead. Bottleneck analysis revealed that the T2→T3 segment (ElastAlert polling) dominates latency in four of five scenarios, contributing 92–98% of total MTTD, while the bottleneck in the malware with VirusTotal scenario shifts to the T1→T2 segment (VirusTotal enrichment, averaging 24.185 seconds). All hypotheses were confirmed: H1 was partially fulfilled (4 of 5 scenarios met the MTTD ≤ 30 second target), H2 was fully fulfilled (100% success rate), and H3 was confirmed through evidence of improved security information quality — transforming raw events into structured alerts enriched with GeoIP context, signature classification, and threat intelligence analysis. Keywords: honeypot, T-Pot, SIEM, Elastic Stack, ElastAlert, intrusion detection system, MTTD, real-time notification, Telegram, VirusTotal, Cowrie, Dionaea, Suricata
| Item Type: | Thesis (Skripsi) |
|---|---|
| Additional Information: | [No.Panggil: 2210511007] [Pembimbing 1: Henki Bayu Seta] [Pembimbing 2: Hamonangan Kinantan Prabu] [Penguji 1: Widya Cholil] [Penguji 2: Anis Fitri Nur Masruriyah] |
| Uncontrolled Keywords: | honeypot, T-Pot, SIEM, Elastic Stack, ElastAlert, intrusion detection system, MTTD, real-time notification, Telegram, VirusTotal, Cowrie, Dionaea, Suricata |
| Subjects: | Q Science > QA Mathematics > QA75 Electronic computers. Computer science Q Science > QA Mathematics > QA76 Computer software |
| Divisions: | Fakultas Ilmu Komputer > Program Studi Informatika (S1) |
| Depositing User: | MUHAMMAD KAHFI DARMAWAN |
| Date Deposited: | 27 Jul 2026 05:33 |
| Last Modified: | 28 Aug 2026 04:45 |
| URI: | http://repository.upnvj.ac.id/id/eprint/51558 |
Actions (login required)
![]() |
View Item |
