Implementasi Artificial Intelligence untuk Analisis Attack Surface dan Rekomendasi Remediasi Kerentanan Keamanan Berbasis Vulnerability Assessment pada Website UMKM
Original Full-Text Article
Download published version for reading and archivingAbstract
The rapid digitalization of Micro, Small, and Medium Enterprises (MSMEs) in Indonesia has raised the need for adequate website security, yet limited technical resources leave many MSME owners unaware of their platform's security posture. This research designs and implements VulnScope, a web-based vulnerability assessment (VA) system that integrates a Large Language Model (LLM) to analyze the attack surface and generate contextual remediation recommendations. The system is built on the FastAPI framework with eight core scanning modules, an aggressive scanner, and a VAPT Engine that classifies findings based on OWASP Top 10:2021 and CVSS v3.1. Artificial intelligence is integrated through the Claude and Nous Hermes models using an agentic tool-use pattern. Black box functional testing confirmed that all features work as specified. Applied to the MSME website ibadahterpanjang.com, the system detected four vulnerabilities (one Critical, one Medium, two Low) with an overall CRITICAL risk level (score 38/100). The results show that integrating VA with artificial intelligence effectively helps MSME owners independently identify and remediate website security vulnerabilities.
Keywords:
Author Biographies
Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.
Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.
Program Studi Teknik Informatika, Sekolah Tinggi Ilmu Komputer Cipta Karya Informatika, Kota Jakarta Timur, Daerah Khusus Ibukota Jakarta, Indonesia.
How to Cite
This is an open-access article distributed under the terms of the Creative Commons Attribution 4.0 International License .
- Share: You are free to copy, distribute, and transmit the work in any medium or format.
- Adapt: You are free to remix, transform, and build upon the work for any purpose, even commercially.
- Attribution: You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
References
Total: 14 References- Achmad, F. K., Mulyana, D. I., & Akbar, Y. (2022). Implementasi algoritma Dijkstra pada routing protokol OSPF menggunakan perangkat Juniper. Informatics for Educators and Professionals: Journal of Informatics, 7(1), 1–14.
- Arif, S. C., Surapati, U., Akbar, Y., & Hidayat, A. Z. (2025). Optimasi Access Control List (ACL) jaringan dalam menangkal akses ilegal jaringan Cisco. Jurnal Indonesia: Manajemen Informatika dan Komunikasi (JIMIK), 6(3).
- Armadani, A., Nofriansyah, N., & Ibnutama, I. (2022). Analisis keamanan untuk mengetahui vulnerability pada web menggunakan penetration testing. Jurnal SAINTIKOM.
- Author, A., & Author, B. (2022). Kesadaran keamanan siber pada pelaku UMKM di Indonesia. Jurnal Sistem Informasi, 10(2).
- Fahlevi, M. R., & Putri, D. R. D. (2021). Analisis monitoring dan kinerja keamanan jaringan menggunakan Nmap. IT (Informatic Technique) Journal, 9(1).
Similar Articles
Articles sharing related keywords and machine learning classifications:
Most read articles by the same author(s)
Other papers published by author(s) in this journal: