An Integrated System for Automated Threat Detection and Response Using Wazuh, Suricata and Telegram

Authors

Arfa Nadia Mohamad Nizam

Department of Cyber Security, Fakulti Kecerdasan Buatan dan Keselamatan Siber, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka, Malaysia, (Malaysia)

Nur Fadzilah Othman

Department of Cyber Security, Fakulti Kecerdasan Buatan dan Keselamatan Siber, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka, Malaysia, (Malaysia)

Syarulnaziah Anawar

Center for Advanced Computing Technology, Fakulti Teknologi Maklumat dan Komunikasi, Universiti Teknikal Malaysia Melaka, Malaysia, (Malaysia)

Zakiah Ayop

Center for Advanced Computing Technology, Fakulti Teknologi Maklumat dan Komunikasi, Universiti Teknikal Malaysia Melaka, Malaysia, (Malaysia)

Sofia Najwa Ramli

Faculty of Computer Science and Information Technology, University Tun Hussein Onn Malaysia, Batu Pahat Johor, Malaysia (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100900237

Subject Category: Computer Science

Volume/Issue: 10/9 | Page No: 3567-3580

Publication Timeline

Submitted: 2026-09-16

Accepted: 2026-09-21

Published: 2026-10-07

Abstract

The increasing speed and diversity of cyberattacks require security monitoring systems that progress from detection to timely and controlled containment. This study developed an integrated framework that combines Suricata network intrusion detection, Wazuh event correlation and Active Response, and Telegram notification. The framework was implemented in an isolated VirtualBox laboratory using a Kali Linux attacker at 192.168.218.128 and an Ubuntu security host at 192.168.218.132. Five controlled scenarios were evaluated: port scanning, Secure Shell (SSH) brute force, Synchronize (SYN) flood, Structured Query Language (SQL) injection, and reverse shell. A scenario passed only when the correct Wazuh detection, Telegram notification, independently verified automated response, timed removal, and recovery evidence were observed. All five scenario-level tests passed, giving a functional test pass rate of 5/5 under the tested configuration. The mean detection-to-response delay was 0.727 seconds, with a maximum of 2.000 seconds, while the mean recovery time was 61.770 seconds. The principal contribution is an auditable, attack-specific closed loop that links detection, correlation, notification, containment, rollback, and recovery rather than treating alert delivery as evidence of mitigation. Because each scenario was executed once and benign control traffic was not included, the result is proof-of-concept functional validation and not general detection accuracy, reliability, precision, or recall.

Keywords

: Wazuh, Suricata, Telegram, Intrusion Detection System, Active Response, Security Orchestration Automation and Response, Automated Incident Response, Functional Testing

Downloads

References

1. K. Scarfone and P. Mell, Guide to Intrusion Detection and Prevention Systems (IDPS), NIST Special Publication 800-94, National Institute of Standards and Technology, 2007. [Google Scholar] [Crossref]

2. https://doi.org/10.6028/NIST.SP.800-94 [Google Scholar] [Crossref]

3. A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST Special Publication 800-61 Revision 3, National Institute of Standards and Technology, 2025. [Google Scholar] [Crossref]

4. https://doi.org/10.6028/NIST.SP.800-61r3 [Google Scholar] [Crossref]

5. Open Information Security Foundation, Suricata Documentation: Rules and EVE JSON Output, 2025. https://docs.suricata.io/ [Google Scholar] [Crossref]

6. E. Albin and N. C. Rowe, “A realistic experimental comparison of the Suricata and Snort intrusion-detection systems,” in Proc. 26th International Conference on Advanced Information Networking and Applications Workshops, 2012, pp. 122–127. https://doi.org/10.1109/WAINA.2012.29 [Google Scholar] [Crossref]

7. D. Fadhilah and M. I. Marzuki, “Performance analysis of IDS Snort and IDS Suricata with many-core processor in virtual machines against DoS/DDoS attacks,” in Proc. 2nd International Conference on Broadband Communications, Wireless Sensors and Powering, 2020. [Google Scholar] [Crossref]

8. https://doi.org/10.1109/BCWSP50066.2020.9249449 [Google Scholar] [Crossref]

9. Wazuh, Wazuh Documentation: Log Data Collection and Active Response, 2025. [Google Scholar] [Crossref]

10. https://documentation.wazuh.com/ [Google Scholar] [Crossref]

11. Telegram, Telegram Bot API, 2025. https://core.telegram.org/bots/api [Google Scholar] [Crossref]

12. A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, article 20, 2019. [Google Scholar] [Crossref]

13. https://doi.org/10.1186/s42400-019-0038-7 [Google Scholar] [Crossref]

14. T. Suryantoro, B. D. P. Purnomosidi, and W. Andriyani, “The analysis of attacks against port 80 webserver with SIEM Wazuh using detection and OSCAR methods,” in Proc. 5th International Seminar on Research of Information Technology and Intelligent Systems, 2022. [Google Scholar] [Crossref]

15. https://doi.org/10.1109/ISRITI56927.2022.10052950 [Google Scholar] [Crossref]

16. Wazuh, “Network IDS integration: Integrating Suricata with Wazuh,” Proof of Concept Guide, 2025. https://documentation.wazuh.com/current/proof-of-concept-guide/integratenetwork-ids-suricata.html [Google Scholar] [Crossref]

17. Wazuh, “Custom Active Response scripts,” Active Response Documentation, 2025. [Google Scholar] [Crossref]

18. https://documentation.wazuh.com/current/user-manual/capabilities/activeresponse/custom-active-response-scripts.html [Google Scholar] [Crossref]

19. J. Kinyua and L. Awuah, “AI/ML in security orchestration, automation and response: Future research directions,” Intelligent Automation & Soft Computing, vol. 28, no. 2, 2021. [Google Scholar] [Crossref]

20. https://doi.org/10.32604/iasc.2021.016240 [Google Scholar] [Crossref]

21. National Institute of Standards and Technology, “Security orchestration, automation, and response,” CSRC Glossary, 2025. [Google Scholar] [Crossref]

22. https://csrc.nist.gov/glossary/term/security_orchestration_automation_and_response [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles