OTOMASI RESPONS INSIDEN TERHADAP SERANGAN PATH TRAVERSAL MENGGUNAKAN LARGE LANGUAGE MODEL (LLM) BERBASIS RETRIEVAL-AUGMENTED GENERATION (RAG)

Febriansyah, Febriansyah and abdurrasyid, abdurrasyid (2026) OTOMASI RESPONS INSIDEN TERHADAP SERANGAN PATH TRAVERSAL MENGGUNAKAN LARGE LANGUAGE MODEL (LLM) BERBASIS RETRIEVAL-AUGMENTED GENERATION (RAG). Diploma thesis, Institut Teknologi PLN.

[thumbnail of COVER.pdf] Text
COVER.pdf

Download (171kB)
[thumbnail of LEMBAR-PENGESAHAN.pdf] Text
LEMBAR-PENGESAHAN.pdf
Restricted to Registered users only

Download (195kB)
[thumbnail of ABSTRAK.pdf] Text
ABSTRAK.pdf

Download (221kB)
[thumbnail of BAB-1.pdf] Text
BAB-1.pdf

Download (228kB)
[thumbnail of BAB-2.pdf] Text
BAB-2.pdf

Download (466kB)
[thumbnail of BAB-3.pdf] Text
BAB-3.pdf
Restricted to Registered users only

Download (3MB)
[thumbnail of BAB-4.pdf] Text
BAB-4.pdf
Restricted to Registered users only

Download (855kB)
[thumbnail of BAB-5.pdf] Text
BAB-5.pdf
Restricted to Registered users only

Download (215kB)
[thumbnail of DAFTAR-PUSTAKA.pdf] Text
DAFTAR-PUSTAKA.pdf

Download (206kB)
[thumbnail of 202231049_Febriansyah_Skripsi.pdf] Text
202231049_Febriansyah_Skripsi.pdf
Restricted to Registered users only

Download (7MB)

Abstract

Serangan path traversal (kerentanan No. 1 versi OWASP) terus membebani analis pusat operasi keamanan akibat tingginya volume peringatan dan analisis manual. Meski Large Language Model (LLM) potensial untuk otomasi respons insiden, keterbatasan domain spesifik dan halusinasi masih menjadi kendala. Penelitian ini mengevaluasi integrasi LLM, arsitektur retrieval-augmented generation (RAG), serta prompt engineering untuk mengatasi tantangan tersebut. Menggunakan design research methodology, tiga model LLM (Llama 3.1 8B, Mistral 7B Instruct, Qwen 2.5 7B) dievaluasi pada 166 entri log audit ModSecurity. Teknik prompting zero-shot, few-shot, dan chaining diuji melalui confusion matrix serta metrik RAGAS. Integrasi RAG dan prompt chaining terbukti konsisten menekan kesalahan klasifikasi. Kombinasi Qwen 2.5 7B mencapai performa sempurna pada accuracy, precision, recall, dan f1-score (skor 1.000). Namun, skor factual correctness RAGAS berada pada rentang moderat (0,0845–0,2115), mengindikasikan model belum konsisten menyertakan pemetaan standar keamanan pada narasinya. Temuan ini membuktikan klasifikasi serangan dan analisis teknis merupakan dua dimensi kualitas yang independen. Penelitian merekomendasikan Qwen 2.5 7B dengan RAG dan prompt chaining sebagai deteksi tahap awal, dengan catatan keluaran narasinya tetap memerlukan tinjauan analis manusia saat pelaporan.

Path traversal attacks (OWASP No. 1 vulnerability) burdening security operations center (SOC) analysts with high alert volumes and manual analysis. While Large Language Models (LLMs) show promise for automating incident response, domain specificity gaps and hallucination risks remain key obstacles. This study evaluates the integration of LLMs, retrieval-augmented generation (RAG), and prompt engineering to address these limitations. Using a design research methodology, three LLMs (Llama 3.1 8B, Mistral 7B Instruct, and Qwen 2.5 7B) were evaluated on 166 ModSecurity audit log entries across zero-shot, few-shot, and prompt chaining techniques, assessed via confusion matrix and RAGAS metrics. Integrating RAG with prompt chaining consistently reduced classification errors, with the Qwen 2.5 7B combination achieving perfect scores (1.000) in accuracy, precision, recall, and f1-score. However, the RAGAS factual correctness score remained moderate (0.0845–0.2115), indicating inconsistent explicit mapping to formal security standards within mitigation narratives. These findings demonstrate that attack classification capability and analytical depth are independent quality dimensions. The study recommends deploying Qwen 2.5 7B with RAG and prompt chaining as an early-stage detection engine to reduce analyst workload, while emphasizing that its narrative output still requires human analyst review during the reporting phase.

Item Type: Thesis (Diploma)
Uncontrolled Keywords: Deteksi serangan siber, Model bahasa besar, Otomasi respons insiden, Retrieval-augmented generation, Path traversal Cyberattack detection, Incident response automation, Large language model, Path traversal attack, Retrieval-augmented generation
Subjects: Bidang Keilmuan > Artificial Intelligence
Bidang Keilmuan > Augmented Reality
Bidang Keilmuan > Classification
Bidang Keilmuan > Data Mining
Bidang Keilmuan > Decision Making
Bidang Keilmuan > Information retrieval
Bidang Keilmuan > Machine Learning
Skripsi
Bidang Keilmuan > Teknik Informatika
Divisions: Fakultas Telematika Energi > S1 Teknik Informatika
Depositing User: FAKULTAS TELEMATIKA ENERGI
Date Deposited: 18 Aug 2026 07:12
Last Modified: 18 Sep 2026 07:24
URI: https://repository.itpln.ac.id/id/eprint/6995

Actions (login required)

View Item
View Item