Scientific Journal of Informatics
Vol 11, No 1 (2024): February 2024

Analysis of Attack Detection on Log Access Servers Using Machine Learning Classification: Integrating Expert Labeling and Optimal Model Selection

Mohammad Ridwan (Faculty of Engineering, Universitas Islam Syekh Yusuf Tangerang, Indonesia)
Irwan Sembiring (Faculty of Science and Mathematics, Universitas Kristen Satya Wacana Salatiga, Indonesia)
Adi Setiawan (Faculty of Science and Mathematics, Universitas Kristen Satya Wacana Salatiga, Indonesia)
Iwan Setyawan (Faculty of Science and Mathematics, Universitas Kristen Satya Wacana Salatiga, Indonesia)



Article Info

Publish Date
28 Feb 2024

Abstract

Purpose: As the complexity and diversity of cyberattacks continue to grow, traditional security measures fall short in effectively countering these threats within web-based environments. Therefore, there is an urgent need to develop and implement innovative, advanced techniques tailored specifically to detect and address these evolving security risks within web applications.Methods: This research focuses on analyzing attack detection in log access servers using machine learning classification with two primary approaches: expert labeling integration and best model selection. Expert labeling determines whether log entries are safe or indicate an attack.Result: Validation in labeling was applied using different datasets to minimize errors and increase confidence in the resulting dataset. Experimental results show that the Decision Tree and Random Forest models have nearly identical accuracy rates, around 89.3%-89.4%, while the ANN model has an accuracy of 81%.Novelty: This study proposes a fusion of expert knowledge in labeling log entries with a rigorous process of selecting the best classification model. This integration has not been extensively explored in previous research, offering a novel approach to enhancing attack detection within web applications. The research contribution lies in the integration of expert security assessment and the selection of the best model for detecting attacks on server access logs, along with validating labels using various datasets from different log devices to enhance confidence in the analysis results.

Copyrights © 2024






Journal Info

Abbrev

SJI

Publisher

Subject

Computer Science & IT

Description

Scientific Journal of Informatics published by the Department of Computer Science, Semarang State University, a scientific journal of Information Systems and Information Technology which includes scholarly writings on pure research and applied research in the field of information systems and ...