INTEGRATION OF SURICATA'S INTRUSION PREVENTION SYSTEM (IPS) ON NGINX LEAST CONNECTION LOAD BALANCER FOR DDOS ATTACK MITIGATION

FITRADHI, NOOR RAVI (2026) INTEGRATION OF SURICATA'S INTRUSION PREVENTION SYSTEM (IPS) ON NGINX LEAST CONNECTION LOAD BALANCER FOR DDOS ATTACK MITIGATION. Undergraduate thesis, UPN Veteran Jawa Timur.

[img] Text (Cover)
19081010115_cover .pdf

Download (1MB)
[img] Text (Bab 1)
19081010115_bab1.pdf

Download (234kB)
[img] Text (Bab 2)
19081010115_bab2.pdf
Restricted to Repository staff only until 23 July 2029.

Download (386kB)
[img] Text (Bab 3)
19081010115_bab3.pdf
Restricted to Repository staff only until 23 July 2029.

Download (418kB)
[img] Text (Bab 4)
19081010115_bab4.pdf
Restricted to Repository staff only until 23 July 2029.

Download (1MB)
[img] Text (Bab 5)
19081010115_bab5.pdf

Download (188kB)
[img] Text (Daftar Pustaka)
19081010115_daftarpustaka.pdf

Download (184kB)

Abstract

Distributed Denial of Service (DDoS) attacks are threats that can disrupt service availability by flooding servers with excess traffic. This study aims to implement and evaluate the integration of Suricata's Intrusion Prevention System (IPS) with NGINX Load Balancer using the Least Connection method to mitigate DDoS attacks. The test was conducted under normal conditions as well as when facing SYN Flood, UDP Flood, and HTTP Flood attacks with throughput, response time, CPU utilization, and mitigation effectiveness parameters. Under normal conditions, the system produces a throughput of 5987.63 req/s with a response time of 8,351 ms. During a SYN Flood attack without IPS, the throughput decreases to 3153.53 req/s and the response time increases to 158,553 ms, while with IPS the throughput increases to 4035.82 req/s and the response time becomes 43,891 ms. In UDP Flood attacks, throughput increased from 4028.18 req/s to 4982.31 req/s and response time improved from 112.028 ms to 24.831 ms after IPS was activated. In the HTTP Flood attack, the throughput increased from 2588.32 req/s to 3450.27 req/s and the response time became faster from 193.175 ms to 54.042 ms. Suricata also managed to block 2,263,680 SYN Flood packages, 65,035 UDP Flood events, and 9,169 HTTP Flood events. The results show that the integration of Suricata IPS and NGINX Load Balancer is effective in improving the performance and resilience of the system to DDoS attacks.

Item Type: Thesis (Undergraduate)
Contributors:
ContributionContributorsNIDN/NIDKEmail
Thesis advisorWahanani, Henni EndahNIDN0022097811henniendah@upnjatim.ac.id
Thesis advisorJunaidi, AchmadNIDN0710117803achmadjuanidi.if@upnjatim.ac.id
Subjects: T Technology > T Technology (General)
Divisions: Faculty of Computer Science > Departemen of Informatics
Depositing User: Unnamed user with email 19081010115@student.upnjatim.ac.id
Date Deposited: 23 Jul 2026 03:28
Last Modified: 23 Jul 2026 03:43
URI: https://repository.upnjatim.ac.id/id/eprint/57936

Actions (login required)

View Item View Item