Implementasi Artificial Intelligence untuk Analisis Attack Surface dan Rekomendasi Remediasi Kerentanan Keamanan Berbasis Vulnerability Assessment pada Website UMKM

Authors

  • Willy Wijayanto Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika
  • Yuma Akbar Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika
  • Mesra Betty Yel Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika

DOI:

https://doi.org/10.63447/jimik.v7i3.2005

Keywords:

Vulnerability Assessment, Large Language Model, Attack Surface, OWASP Top 10, CVSS, MSME Website Security

Abstract

The rapid digitalization of Micro, Small, and Medium Enterprises (MSMEs) in Indonesia has raised the need for adequate website security, yet limited technical resources leave many MSME owners unaware of their platform's security posture. This research designs and implements VulnScope, a web-based vulnerability assessment (VA) system that integrates a Large Language Model (LLM) to analyze the attack surface and generate contextual remediation recommendations. The system is built on the FastAPI framework with eight core scanning modules, an aggressive scanner, and a VAPT Engine that classifies findings based on OWASP Top 10:2021 and CVSS v3.1. Artificial intelligence is integrated through the Claude and Nous Hermes models using an agentic tool-use pattern. Black box functional testing confirmed that all features work as specified. Applied to the MSME website ibadahterpanjang.com, the system detected four vulnerabilities (one Critical, one Medium, two Low) with an overall CRITICAL risk level (score 38/100). The results show that integrating VA with artificial intelligence effectively helps MSME owners independently identify and remediate website security vulnerabilities.

Downloads

Download data is not yet available.

Author Biographies

  • Willy Wijayanto, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika

    Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.

  • Yuma Akbar, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika

    Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.

  • Mesra Betty Yel, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika

    Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.

References

Achmad, F. K., Mulyana, D. I., & Akbar, Y. (2022). Implementasi algoritma Dijkstra pada routing protokol OSPF menggunakan perangkat Juniper. Informatics for Educators and Professionals: Journal of Informatics, 7(1), 1–14.

Arif, S. C., Surapati, U., Akbar, Y., & Hidayat, A. Z. (2025). Optimasi Access Control List (ACL) jaringan dalam menangkal akses ilegal jaringan Cisco. Jurnal Indonesia: Manajemen Informatika dan Komunikasi (JIMIK), 6(3).

Armadani, A., Nofriansyah, N., & Ibnutama, I. (2022). Analisis keamanan untuk mengetahui vulnerability pada web menggunakan penetration testing. Jurnal SAINTIKOM.

Author, A., & Author, B. (2022). Kesadaran keamanan siber pada pelaku UMKM di Indonesia. Jurnal Sistem Informasi, 10(2).

Fahlevi, M. R., & Putri, D. R. D. (2021). Analisis monitoring dan kinerja keamanan jaringan menggunakan Nmap. IT (Informatic Technique) Journal, 9(1).

Fang, R., Bindu, R., Gupta, A., & Kang, D. (2024). LLM agents can autonomously exploit one-day vulnerabilities. arXiv preprint arXiv:2404.08144.

Kaspersky. (2022). Cyber threats to small and medium businesses. Kaspersky Security Bulletin.

Kementerian Koperasi dan UKM Republik Indonesia. (2023). Perkembangan UMKM dan transformasi digital di Indonesia. Jakarta.

Ollama. (2024). Run large language models locally. GitHub Repository.

Ramesh, S., & Author, T. (2025). Machine learning for cybersecurity applications. Computers & Security, 154.

Riadi, I., Prayudi, Y., & Author, A. (2020). Analisis keamanan website menggunakan metode vulnerability assessment. Jurnal Teknologi Informasi, 9(1).

Sai, S., Yashvardhan, U., Chamola, V., & Sikdar, B. (2024). Generative AI for cyber security. IEEE Access, 12.

Sasmito, G. W., & Nishom, M. (2020). Testing the population administration website application using black box testing boundary value analysis. Dalam Proceedings of the 2020 IEEE International Conference on Open Systems (ICOS).

Supangat, A., Amna, D., & Rochman, F. (2025). Penetration testing and vulnerability analysis to strengthen data protection. Journal of Information Technology and Cyber Security.

Downloads

Published

2026-09-10

Issue

Section

Articles

How to Cite

Implementasi Artificial Intelligence untuk Analisis Attack Surface dan Rekomendasi Remediasi Kerentanan Keamanan Berbasis Vulnerability Assessment pada Website UMKM. (2026). Jurnal Indonesia : Manajemen Informatika Dan Komunikasi, 7(3), 462-468. https://doi.org/10.63447/jimik.v7i3.2005

Similar Articles

1-10 of 298

You may also start an advanced similarity search for this article.

Most read articles by the same author(s)

<< < 1 2 3 > >>