Pengembangan Aplikasi Deteksi Ancaman Siber Real-Time Berbasis Analisis Log Menggunakan Machine Learning dengan Notifikasi Peringatan Otomatis

Authors

  • Qhodry Andra Wijaya ID Universitas Negeri Padang
  • Hadi Kurnia Saputra ID Universitas Negeri Padang
  • Khairi Budayawan ID Universitas Negeri Padang
  • Titi Sri Wahyuni ID Universitas Negeri Padang

DOI:

https://doi.org/10.36312/y98nvh32

Abstract

Penelitian ini mengembangkan aplikasi deteksi ancaman siber real-time berbasis analisis Apache access log dengan dukungan machine learning dan notifikasi otomatis. Permasalahan utama yang diangkat adalah keterlambatan deteksi ketika administrator masih memeriksa log secara manual, padahal pola serangan web seperti SQL Injection, Cross-Site Scripting, Directory Traversal, dan Brute Force dapat muncul sebagai rangkaian request singkat yang memerlukan respons cepat. Sistem dikembangkan menggunakan model prototipe dengan frontend Next.js, backend FastAPI, database PostgreSQL, pipeline analitik Python, serta Telegram Bot sebagai kanal peringatan. Dataset awal berjumlah 56.757 baris dan diproses melalui pembersihan, ekstraksi fitur perilaku dan signature, deteksi anomali Isolation Forest, klasterisasi DBSCAN, penyeimbangan SMOTE, serta klasifikasi Random Forest. Hasil evaluasi menunjukkan bahwa DBSCAN mencapai Silhouette Score 0,4788, sedangkan Random Forest memperoleh akurasi keseluruhan 0,9971 pada 10.874 data uji dengan performa sangat tinggi pada kelas Normal, SQL Injection, XSS, Directory Traversal, dan Brute Force. Pengujian fungsional menghasilkan seluruh skenario valid, sementara pengujian real-time menunjukkan rata-rata latensi 3,357 detik dari serangan masuk sampai notifikasi diterima. Temuan ini menunjukkan bahwa integrasi analisis log, machine learning, dashboard, dan notifikasi dapat meningkatkan visibilitas keamanan serta mendukung peringatan dini pada server web.

This study develops a real-time cyber threat detection application based on Apache access log analysis using machine learning and automated alert notification. The main problem addressed is delayed threat detection when administrators still inspect logs manually, whereas web attack patterns such as SQL Injection, Cross-Site Scripting, Directory Traversal, and Brute Force may occur as short sequences of requests requiring immediate response. The system was developed using a prototyping model with a Next.js frontend, FastAPI backend, PostgreSQL database, Python analytical pipeline, and Telegram Bot as the alert channel. The initial dataset contained 56,757 rows and was processed through cleaning, behavioral and signature-based feature extraction, Isolation Forest anomaly detection, DBSCAN clustering, SMOTE balancing, and Random Forest classification. The evaluation indicates that DBSCAN achieved a Silhouette Score of 0.4788, while Random Forest obtained an overall accuracy of 0.9971 on 10,874 test instances with strong performance across Normal, SQL Injection, XSS, Directory Traversal, and Brute Force classes. Functional testing confirmed that all scenarios were valid, and real-time testing showed an average latency of 3.357 seconds from attack arrival to alert reception. These findings demonstrate that the integration of log analysis, machine learning, dashboards, and notification services can improve security visibility and support early warning on web servers.

Downloads

Published

2026-05-11

Issue

Section

Articles

How to Cite

Wijaya, Q. A., Saputra, H. K. ., Budayawan, K. ., & Wahyuni, T. S. . (2026). Pengembangan Aplikasi Deteksi Ancaman Siber Real-Time Berbasis Analisis Log Menggunakan Machine Learning dengan Notifikasi Peringatan Otomatis. Journal of Authentic Research, 5(2), 2344-2361. https://doi.org/10.36312/y98nvh32