Implementasi Artificial Intelligence untuk Analisis Attack Surface dan Rekomendasi Remediasi Kerentanan Keamanan Berbasis Vulnerability Assessment pada Website UMKM
DOI:
https://doi.org/10.63447/jimik.v7i3.2005Keywords:
Vulnerability Assessment, Large Language Model, Attack Surface, OWASP Top 10, CVSS, MSME Website SecurityAbstract
The rapid digitalization of Micro, Small, and Medium Enterprises (MSMEs) in Indonesia has raised the need for adequate website security, yet limited technical resources leave many MSME owners unaware of their platform's security posture. This research designs and implements VulnScope, a web-based vulnerability assessment (VA) system that integrates a Large Language Model (LLM) to analyze the attack surface and generate contextual remediation recommendations. The system is built on the FastAPI framework with eight core scanning modules, an aggressive scanner, and a VAPT Engine that classifies findings based on OWASP Top 10:2021 and CVSS v3.1. Artificial intelligence is integrated through the Claude and Nous Hermes models using an agentic tool-use pattern. Black box functional testing confirmed that all features work as specified. Applied to the MSME website ibadahterpanjang.com, the system detected four vulnerabilities (one Critical, one Medium, two Low) with an overall CRITICAL risk level (score 38/100). The results show that integrating VA with artificial intelligence effectively helps MSME owners independently identify and remediate website security vulnerabilities.
Downloads
References
Achmad, F. K., Mulyana, D. I., & Akbar, Y. (2022). Implementasi algoritma Dijkstra pada routing protokol OSPF menggunakan perangkat Juniper. Informatics for Educators and Professionals: Journal of Informatics, 7(1), 1–14.
Arif, S. C., Surapati, U., Akbar, Y., & Hidayat, A. Z. (2025). Optimasi Access Control List (ACL) jaringan dalam menangkal akses ilegal jaringan Cisco. Jurnal Indonesia: Manajemen Informatika dan Komunikasi (JIMIK), 6(3).
Armadani, A., Nofriansyah, N., & Ibnutama, I. (2022). Analisis keamanan untuk mengetahui vulnerability pada web menggunakan penetration testing. Jurnal SAINTIKOM.
Author, A., & Author, B. (2022). Kesadaran keamanan siber pada pelaku UMKM di Indonesia. Jurnal Sistem Informasi, 10(2).
Fahlevi, M. R., & Putri, D. R. D. (2021). Analisis monitoring dan kinerja keamanan jaringan menggunakan Nmap. IT (Informatic Technique) Journal, 9(1).
Fang, R., Bindu, R., Gupta, A., & Kang, D. (2024). LLM agents can autonomously exploit one-day vulnerabilities. arXiv preprint arXiv:2404.08144.
Kaspersky. (2022). Cyber threats to small and medium businesses. Kaspersky Security Bulletin.
Kementerian Koperasi dan UKM Republik Indonesia. (2023). Perkembangan UMKM dan transformasi digital di Indonesia. Jakarta.
Ollama. (2024). Run large language models locally. GitHub Repository.
Ramesh, S., & Author, T. (2025). Machine learning for cybersecurity applications. Computers & Security, 154.
Riadi, I., Prayudi, Y., & Author, A. (2020). Analisis keamanan website menggunakan metode vulnerability assessment. Jurnal Teknologi Informasi, 9(1).
Sai, S., Yashvardhan, U., Chamola, V., & Sikdar, B. (2024). Generative AI for cyber security. IEEE Access, 12.
Sasmito, G. W., & Nishom, M. (2020). Testing the population administration website application using black box testing boundary value analysis. Dalam Proceedings of the 2020 IEEE International Conference on Open Systems (ICOS).
Supangat, A., Amna, D., & Rochman, F. (2025). Penetration testing and vulnerability analysis to strengthen data protection. Journal of Information Technology and Cyber Security.
Downloads
Published
Issue
Section
License
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License (CC-BY 4.0) that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.
