Proyek ini adalah implementasi Intrusion Detection System (IDS) menggunakan Snort yang diintegrasikan dengan Telegram Bot. Sistem ini berfungsi untuk mendeteksi berbagai jenis anomali jaringan dan pemindaian (seperti Ping dan Nmap) serta mengirimkan notifikasi peringatan (alert) secara real-time ke Telegram.
Attacker ➡️ Snort IDS ➡️ Log File ➡️ Python Script ➡️ Telegram Bot ➡️ User
- Sistem operasi Linux (Ubuntu/Debian direkomendasikan).
- Snort telah terinstal (
sudo apt install snort). - Python 3 terinstal.
- Koneksi internet untuk mengirim pesan ke API Telegram.
Atur rules untuk mendeteksi aktivitas spesifik seperti ICMP Ping, Nmap ICMP Scan, dan Nmap SYN Scan. Tambahkan rules ini ke dalam file lokal rules Snort Anda (contoh: /etc/snort/rules/local.rules):
# Deteksi Ping biasa
alert icmp any any -> any any (msg:"ICMP Ping Detected"; itype:8; detection_filter:track by_src, count 1, seconds 5; sid:1000001; rev:3;)
# Deteksi Pemindaian NMAP ICMP
alert icmp any any -> any any (msg:"NMAP ICMP Scan Detected"; itype:8; detection_filter:track by_src, count 30, seconds 1; sid:1000002; rev:3;)
# Deteksi Pemindaian NMAP SYN Scan
alert tcp any any -> any any (msg:"NMAP SYN Scan Detected"; flags:S; detection_filter:track by_src, count 20, seconds 3; sid:1000003; rev:1;)
- Buka aplikasi Telegram dan cari @BotFather.
- Ketik
/newbotdan ikuti instruksi untuk membuat bot baru. - Simpan BOT TOKEN yang diberikan.
- Cari tahu CHAT ID Anda (Anda bisa menggunakan bot pencari Chat ID seperti
@userinfobot).
Script ini akan membaca file log Snort (snort.alert.fast) secara real-time dan mengirimkannya ke Telegram.
Pastikan Anda menginstal pustaka yang diperlukan:
pip install requestsBuat file bernama bot.py dan salin kode berikut. Pastikan untuk mengganti BOT_TOKEN dan CHAT_ID dengan milik Anda:
import time
import requests
import re
# ================= CONFIG =================
BOT_TOKEN = "ISI_TOKEN_KAMU"
CHAT_ID = "ISI_CHAT_ID_KAMU"
LOG_FILE = "/var/log/snort/snort.alert.fast"
# ==========================================
def send_telegram(message):
try:
requests.post(
f"https://api.telegram.org/bot{BOT_TOKEN}/sendMessage",
data={
"chat_id": CHAT_ID,
"text": message
}
)
except Exception as e:
print("Error kirim:", e)
def follow(file):
file.seek(0, 2)
while True:
line = file.readline()
if not line:
time.sleep(0.2)
continue
yield line
def parse_alert(line):
try:
time_part = line.split()[0]
alert_type_match = re.search(r'\] (.*?) \[\*\*\]', line)
alert_type = alert_type_match.group(1) if alert_type_match else "Unknown"
proto_match = re.search(r'\{(.*?)\}', line)
proto = proto_match.group(1) if proto_match else "Unknown"
ip_match = re.search(r'([0-9a-fA-F:\.]+)\s*->\s*([0-9a-fA-F:\.]+)', line)
if ip_match:
src = ip_match.group(1)
dst = ip_match.group(2)
else:
src = "Unknown"
dst = "Unknown"
level = "⚠️"
category = "UNKNOWN"
if "NMAP ICMP Scan" in alert_type:
level = "🔴 HIGH"
category = "NMAP ICMP SCAN"
elif "NMAP SYN Scan" in alert_type:
level = "🔴 HIGH"
category = "NMAP SYN SCAN"
elif "ICMP Ping" in alert_type:
level = "🟢 INFO"
category = "PING"
elif "HTTP" in alert_type.upper():
level = "🟠 MEDIUM"
category = "HTTP ACTIVITY"
elif proto == "TCP":
level = "🟡 MEDIUM"
category = "TCP ACTIVITY"
elif proto == "ICMP":
level = "🟢 INFO"
category = "ICMP ACTIVITY"
method = ""
if "GET" in line:
method = "GET"
elif "POST" in line:
method = "POST"
message = f"""🚨 SNORT ALERT
{level} {category}
🕒 Time : {time_part}
🌐 Source : {src}
🎯 Target : {dst}
📊 Proto : {proto}"""
if method:
message += f"\n🌍 Method : {method}"
message += f"\n📝 Info : {alert_type}"
return message
except Exception as e:
print("Parsing error:", e)
return None
# ================= MAIN =================
if __name__ == "__main__":
print("🚀 Monitoring Snort alert (FINAL VERSION)...")
last_line = ""
with open(LOG_FILE, "r") as logfile:
for line in follow(logfile):
if not any(x in line for x in ["ICMP", "TCP", "HTTP"]):
continue
if line == last_line:
continue
last_line = line
print("LOG:", line.strip())
msg = parse_alert(line)
if msg:
print(msg)
send_telegram(msg)
time.sleep(0.5)Pertama, jalankan Snort dalam mode IDS di terminal pengawasan (ubah enp0s3 dengan interface jaringan Anda):
sudo snort -A fast -q -c /etc/snort/snort.conf -i enp0s3Kedua, jalankan script Python di terminal lainnya untuk memonitor log file:
sudo python3 bot.py(Catatan: Anda mungkin memerlukan akses sudo jika izin log file Snort bersifat root-only).
Anda dapat menguji fungsi IDS dengan cara menggunakan device lain di jaringan untuk menyerang mesin ini:
- Ping:
ping <IP_Target>-> Terdeteksi sebagai 🟢 INFO - Nmap ICMP:
nmap -sn <IP_Target>-> Terdeteksi sebagai 🔴 HIGH ALERT - HTTP/TCP: -> Terdeteksi sebagai 🟠 / 🟡 MEDIUM
Sistem berhasil mendeteksi serangan dan mengirim laporan real-time ke Telegram terkait status jaringan. Sangat cocok sebagai implementasi monitoring jaringan skala kecil.