Skip to content

About

"Implementasi Intrusion Detection System (IDS) menggunakan Snort dengan integrasi notifikasi real-time via Telegram Bot untuk memonitor aktivitas jaringan."

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Snort IDS with Telegram Bot Notifier

Proyek ini adalah implementasi Intrusion Detection System (IDS) menggunakan Snort yang diintegrasikan dengan Telegram Bot. Sistem ini berfungsi untuk mendeteksi berbagai jenis anomali jaringan dan pemindaian (seperti Ping dan Nmap) serta mengirimkan notifikasi peringatan (alert) secara real-time ke Telegram.

🏗️ Arsitektur Sistem

Attacker ➡️ Snort IDS ➡️ Log File ➡️ Python Script ➡️ Telegram Bot ➡️ User

📋 Prasyarat

  • Sistem operasi Linux (Ubuntu/Debian direkomendasikan).
  • Snort telah terinstal (sudo apt install snort).
  • Python 3 terinstal.
  • Koneksi internet untuk mengirim pesan ke API Telegram.

🚀 Langkah-Langkah Implementasi

1. Konfigurasi Rules Snort

Atur rules untuk mendeteksi aktivitas spesifik seperti ICMP Ping, Nmap ICMP Scan, dan Nmap SYN Scan. Tambahkan rules ini ke dalam file lokal rules Snort Anda (contoh: /etc/snort/rules/local.rules):

# Deteksi Ping biasa
alert icmp any any -> any any (msg:"ICMP Ping Detected"; itype:8; detection_filter:track by_src, count 1, seconds 5; sid:1000001; rev:3;)

# Deteksi Pemindaian NMAP ICMP
alert icmp any any -> any any (msg:"NMAP ICMP Scan Detected"; itype:8; detection_filter:track by_src, count 30, seconds 1; sid:1000002; rev:3;)

# Deteksi Pemindaian NMAP SYN Scan
alert tcp any any -> any any (msg:"NMAP SYN Scan Detected"; flags:S; detection_filter:track by_src, count 20, seconds 3; sid:1000003; rev:1;)

2. Membuat Bot Telegram

  1. Buka aplikasi Telegram dan cari @BotFather.
  2. Ketik /newbot dan ikuti instruksi untuk membuat bot baru.
  3. Simpan BOT TOKEN yang diberikan.
  4. Cari tahu CHAT ID Anda (Anda bisa menggunakan bot pencari Chat ID seperti @userinfobot).

3. Mempersiapkan Script Python

Script ini akan membaca file log Snort (snort.alert.fast) secara real-time dan mengirimkannya ke Telegram.

Pastikan Anda menginstal pustaka yang diperlukan:

pip install requests

Buat file bernama bot.py dan salin kode berikut. Pastikan untuk mengganti BOT_TOKEN dan CHAT_ID dengan milik Anda:

import time
import requests
import re

# ================= CONFIG =================
BOT_TOKEN = "ISI_TOKEN_KAMU"
CHAT_ID = "ISI_CHAT_ID_KAMU"
LOG_FILE = "/var/log/snort/snort.alert.fast"
# ==========================================

def send_telegram(message):
    try:
        requests.post(
            f"https://api.telegram.org/bot{BOT_TOKEN}/sendMessage",
            data={
                "chat_id": CHAT_ID,
                "text": message
            }
        )
    except Exception as e:
        print("Error kirim:", e)

def follow(file):
    file.seek(0, 2)
    while True:
        line = file.readline()
        if not line:
            time.sleep(0.2)
            continue
        yield line

def parse_alert(line):
    try:
        time_part = line.split()[0]
        alert_type_match = re.search(r'\] (.*?) \[\*\*\]', line)
        alert_type = alert_type_match.group(1) if alert_type_match else "Unknown"
        proto_match = re.search(r'\{(.*?)\}', line)
        proto = proto_match.group(1) if proto_match else "Unknown"

        ip_match = re.search(r'([0-9a-fA-F:\.]+)\s*->\s*([0-9a-fA-F:\.]+)', line)
        if ip_match:
            src = ip_match.group(1)
            dst = ip_match.group(2)
        else:
            src = "Unknown"
            dst = "Unknown"

        level = "⚠️"
        category = "UNKNOWN"

        if "NMAP ICMP Scan" in alert_type:
            level = "🔴 HIGH"
            category = "NMAP ICMP SCAN"
        elif "NMAP SYN Scan" in alert_type:
            level = "🔴 HIGH"
            category = "NMAP SYN SCAN"
        elif "ICMP Ping" in alert_type:
            level = "🟢 INFO"
            category = "PING"
        elif "HTTP" in alert_type.upper():
            level = "🟠 MEDIUM"
            category = "HTTP ACTIVITY"
        elif proto == "TCP":
            level = "🟡 MEDIUM"
            category = "TCP ACTIVITY"
        elif proto == "ICMP":
            level = "🟢 INFO"
            category = "ICMP ACTIVITY"

        method = ""
        if "GET" in line:
            method = "GET"
        elif "POST" in line:
            method = "POST"

        message = f"""🚨 SNORT ALERT

{level} {category}

🕒 Time   : {time_part}
🌐 Source : {src}
🎯 Target : {dst}
📊 Proto  : {proto}"""

        if method:
            message += f"\n🌍 Method : {method}"

        message += f"\n📝 Info   : {alert_type}"
        return message

    except Exception as e:
        print("Parsing error:", e)
        return None

# ================= MAIN =================
if __name__ == "__main__":
    print("🚀 Monitoring Snort alert (FINAL VERSION)...")
    last_line = ""

    with open(LOG_FILE, "r") as logfile:
        for line in follow(logfile):
            if not any(x in line for x in ["ICMP", "TCP", "HTTP"]):
                continue
            if line == last_line:
                continue
            last_line = line
            print("LOG:", line.strip())
            
            msg = parse_alert(line)
            if msg:
                print(msg)
                send_telegram(msg)
                time.sleep(0.5)

4. Menjalankan Sistem

Pertama, jalankan Snort dalam mode IDS di terminal pengawasan (ubah enp0s3 dengan interface jaringan Anda):

sudo snort -A fast -q -c /etc/snort/snort.conf -i enp0s3

Kedua, jalankan script Python di terminal lainnya untuk memonitor log file:

sudo python3 bot.py

(Catatan: Anda mungkin memerlukan akses sudo jika izin log file Snort bersifat root-only).

🧪 Pengujian

Anda dapat menguji fungsi IDS dengan cara menggunakan device lain di jaringan untuk menyerang mesin ini:

  • Ping: ping <IP_Target> -> Terdeteksi sebagai 🟢 INFO
  • Nmap ICMP: nmap -sn <IP_Target> -> Terdeteksi sebagai 🔴 HIGH ALERT
  • HTTP/TCP: -> Terdeteksi sebagai 🟠 / 🟡 MEDIUM

📝 Kesimpulan

Sistem berhasil mendeteksi serangan dan mengirim laporan real-time ke Telegram terkait status jaringan. Sangat cocok sebagai implementasi monitoring jaringan skala kecil.

About

"Implementasi Intrusion Detection System (IDS) menggunakan Snort dengan integrasi notifikasi real-time via Telegram Bot untuk memonitor aktivitas jaringan."

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors