An Integrated System for Automated Threat Detection and Response Using Wazuh, Suricata and Telegram
Authors
Department of Cyber Security, Fakulti Kecerdasan Buatan dan Keselamatan Siber, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka, Malaysia, (Malaysia)
Department of Cyber Security, Fakulti Kecerdasan Buatan dan Keselamatan Siber, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka, Malaysia, (Malaysia)
Center for Advanced Computing Technology, Fakulti Teknologi Maklumat dan Komunikasi, Universiti Teknikal Malaysia Melaka, Malaysia, (Malaysia)
Center for Advanced Computing Technology, Fakulti Teknologi Maklumat dan Komunikasi, Universiti Teknikal Malaysia Melaka, Malaysia, (Malaysia)
Faculty of Computer Science and Information Technology, University Tun Hussein Onn Malaysia, Batu Pahat Johor, Malaysia (Malaysia)
Article Information
DOI: 10.47772/IJRISS.2026.100900237
Subject Category: Computer Science
Volume/Issue: 10/9 | Page No: 3567-3580
Publication Timeline
Submitted: 2026-09-16
Accepted: 2026-09-21
Published: 2026-10-07
Abstract
The increasing speed and diversity of cyberattacks require security monitoring systems that progress from detection to timely and controlled containment. This study developed an integrated framework that combines Suricata network intrusion detection, Wazuh event correlation and Active Response, and Telegram notification. The framework was implemented in an isolated VirtualBox laboratory using a Kali Linux attacker at 192.168.218.128 and an Ubuntu security host at 192.168.218.132. Five controlled scenarios were evaluated: port scanning, Secure Shell (SSH) brute force, Synchronize (SYN) flood, Structured Query Language (SQL) injection, and reverse shell. A scenario passed only when the correct Wazuh detection, Telegram notification, independently verified automated response, timed removal, and recovery evidence were observed. All five scenario-level tests passed, giving a functional test pass rate of 5/5 under the tested configuration. The mean detection-to-response delay was 0.727 seconds, with a maximum of 2.000 seconds, while the mean recovery time was 61.770 seconds. The principal contribution is an auditable, attack-specific closed loop that links detection, correlation, notification, containment, rollback, and recovery rather than treating alert delivery as evidence of mitigation. Because each scenario was executed once and benign control traffic was not included, the result is proof-of-concept functional validation and not general detection accuracy, reliability, precision, or recall.
Keywords
: Wazuh, Suricata, Telegram, Intrusion Detection System, Active Response, Security Orchestration Automation and Response, Automated Incident Response, Functional Testing
Downloads
References
1. K. Scarfone and P. Mell, Guide to Intrusion Detection and Prevention Systems (IDPS), NIST Special Publication 800-94, National Institute of Standards and Technology, 2007. [Google Scholar] [Crossref]
2. https://doi.org/10.6028/NIST.SP.800-94 [Google Scholar] [Crossref]
3. A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST Special Publication 800-61 Revision 3, National Institute of Standards and Technology, 2025. [Google Scholar] [Crossref]
4. https://doi.org/10.6028/NIST.SP.800-61r3 [Google Scholar] [Crossref]
5. Open Information Security Foundation, Suricata Documentation: Rules and EVE JSON Output, 2025. https://docs.suricata.io/ [Google Scholar] [Crossref]
6. E. Albin and N. C. Rowe, “A realistic experimental comparison of the Suricata and Snort intrusion-detection systems,” in Proc. 26th International Conference on Advanced Information Networking and Applications Workshops, 2012, pp. 122–127. https://doi.org/10.1109/WAINA.2012.29 [Google Scholar] [Crossref]
7. D. Fadhilah and M. I. Marzuki, “Performance analysis of IDS Snort and IDS Suricata with many-core processor in virtual machines against DoS/DDoS attacks,” in Proc. 2nd International Conference on Broadband Communications, Wireless Sensors and Powering, 2020. [Google Scholar] [Crossref]
8. https://doi.org/10.1109/BCWSP50066.2020.9249449 [Google Scholar] [Crossref]
9. Wazuh, Wazuh Documentation: Log Data Collection and Active Response, 2025. [Google Scholar] [Crossref]
10. https://documentation.wazuh.com/ [Google Scholar] [Crossref]
11. Telegram, Telegram Bot API, 2025. https://core.telegram.org/bots/api [Google Scholar] [Crossref]
12. A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, article 20, 2019. [Google Scholar] [Crossref]
13. https://doi.org/10.1186/s42400-019-0038-7 [Google Scholar] [Crossref]
14. T. Suryantoro, B. D. P. Purnomosidi, and W. Andriyani, “The analysis of attacks against port 80 webserver with SIEM Wazuh using detection and OSCAR methods,” in Proc. 5th International Seminar on Research of Information Technology and Intelligent Systems, 2022. [Google Scholar] [Crossref]
15. https://doi.org/10.1109/ISRITI56927.2022.10052950 [Google Scholar] [Crossref]
16. Wazuh, “Network IDS integration: Integrating Suricata with Wazuh,” Proof of Concept Guide, 2025. https://documentation.wazuh.com/current/proof-of-concept-guide/integratenetwork-ids-suricata.html [Google Scholar] [Crossref]
17. Wazuh, “Custom Active Response scripts,” Active Response Documentation, 2025. [Google Scholar] [Crossref]
18. https://documentation.wazuh.com/current/user-manual/capabilities/activeresponse/custom-active-response-scripts.html [Google Scholar] [Crossref]
19. J. Kinyua and L. Awuah, “AI/ML in security orchestration, automation and response: Future research directions,” Intelligent Automation & Soft Computing, vol. 28, no. 2, 2021. [Google Scholar] [Crossref]
20. https://doi.org/10.32604/iasc.2021.016240 [Google Scholar] [Crossref]
21. National Institute of Standards and Technology, “Security orchestration, automation, and response,” CSRC Glossary, 2025. [Google Scholar] [Crossref]
22. https://csrc.nist.gov/glossary/term/security_orchestration_automation_and_response [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- What the Desert Fathers Teach Data Scientists: Ancient Ascetic Principles for Ethical Machine-Learning Practice
- Comparative Analysis of Some Machine Learning Algorithms for the Classification of Ransomware
- Comparative Performance Analysis of Some Priority Queue Variants in Dijkstra’s Algorithm
- Transfer Learning in Detecting E-Assessment Malpractice from a Proctored Video Recordings.
- Dual-Modal Detection of Parkinson’s Disease: A Clinical Framework and Deep Learning Approach Using NeuroParkNet