Pengembangan Aplikasi Deteksi Ancaman Siber Real-Time Berbasis Analisis Log Menggunakan Machine Learning dengan Notifikasi Peringatan Otomatis
DOI:
https://doi.org/10.36312/y98nvh32Abstract
Penelitian ini mengembangkan aplikasi deteksi ancaman siber real-time berbasis analisis Apache access log dengan dukungan machine learning dan notifikasi otomatis. Permasalahan utama yang diangkat adalah keterlambatan deteksi ketika administrator masih memeriksa log secara manual, padahal pola serangan web seperti SQL Injection, Cross-Site Scripting, Directory Traversal, dan Brute Force dapat muncul sebagai rangkaian request singkat yang memerlukan respons cepat. Sistem dikembangkan menggunakan model prototipe dengan frontend Next.js, backend FastAPI, database PostgreSQL, pipeline analitik Python, serta Telegram Bot sebagai kanal peringatan. Dataset awal berjumlah 56.757 baris dan diproses melalui pembersihan, ekstraksi fitur perilaku dan signature, deteksi anomali Isolation Forest, klasterisasi DBSCAN, penyeimbangan SMOTE, serta klasifikasi Random Forest. Hasil evaluasi menunjukkan bahwa DBSCAN mencapai Silhouette Score 0,4788, sedangkan Random Forest memperoleh akurasi keseluruhan 0,9971 pada 10.874 data uji dengan performa sangat tinggi pada kelas Normal, SQL Injection, XSS, Directory Traversal, dan Brute Force. Pengujian fungsional menghasilkan seluruh skenario valid, sementara pengujian real-time menunjukkan rata-rata latensi 3,357 detik dari serangan masuk sampai notifikasi diterima. Temuan ini menunjukkan bahwa integrasi analisis log, machine learning, dashboard, dan notifikasi dapat meningkatkan visibilitas keamanan serta mendukung peringatan dini pada server web.
This study develops a real-time cyber threat detection application based on Apache access log analysis using machine learning and automated alert notification. The main problem addressed is delayed threat detection when administrators still inspect logs manually, whereas web attack patterns such as SQL Injection, Cross-Site Scripting, Directory Traversal, and Brute Force may occur as short sequences of requests requiring immediate response. The system was developed using a prototyping model with a Next.js frontend, FastAPI backend, PostgreSQL database, Python analytical pipeline, and Telegram Bot as the alert channel. The initial dataset contained 56,757 rows and was processed through cleaning, behavioral and signature-based feature extraction, Isolation Forest anomaly detection, DBSCAN clustering, SMOTE balancing, and Random Forest classification. The evaluation indicates that DBSCAN achieved a Silhouette Score of 0.4788, while Random Forest obtained an overall accuracy of 0.9971 on 10,874 test instances with strong performance across Normal, SQL Injection, XSS, Directory Traversal, and Brute Force classes. Functional testing confirmed that all scenarios were valid, and real-time testing showed an average latency of 3.357 seconds from attack arrival to alert reception. These findings demonstrate that the integration of log analysis, machine learning, dashboards, and notification services can improve security visibility and support early warning on web servers.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Qhodry Andra Wijaya, Hadi Kurnia Saputra, Khairi Budayawan, Titi Sri Wahyuni

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with Journal of Authentic Research agree to the following terms:
- For all articles published in Journal of Authentic Research, copyright is retained by the authors. Authors give permission to the publisher to announce the work with conditions. When the manuscript is accepted for publication, the authors agrees to implement a non-exclusive transfer of publishing rights to the journals.
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.