Analisis Komparatif Model Deteksi Anomali Pada Web Log Dengan Preprocessing Berbasis Aggregated Features Di Lingkungan AWS Clean Rooms

Situmorang, Aditya (2026) Analisis Komparatif Model Deteksi Anomali Pada Web Log Dengan Preprocessing Berbasis Aggregated Features Di Lingkungan AWS Clean Rooms. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5025221207-Undergraduate_Thesis.pdf] Text
5025221207-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (12MB) | Request a copy

Abstract

Log akses web merekam seluruh aktivitas interaksi pengguna dengan sistem, termasuk pola permintaan yang dapat mencerminkan potensi serangan seperti brute force, scanning, dan eksploitasi endpoint. Karena data log bersifat besar, tidak terstruktur, dan tidak berlabel, pendekatan deteksi anomali berbasis unsupervised learning menjadi relevan untuk mengidentifikasi perilaku abnormal tanpa pelabelan manual. Namun, kolaborasi antar-organisasi dalam skenario ini sering terbentur isu privasi data. Penelitian ini memanfaatkan AWS Clean Rooms sebagai lingkungan analitik terproteksi yang memungkinkan kolaborasi tanpa membagikan data mentah, dikombinasikan dengan preprocessing berbasis aggregated feature engineering menggunakan empat skenario transformasi fitur yaitu Original (ORI), Feature Engineering (FE), Logarithmic (LOG), dan LOG+FE, serta empat variasi time window yaitu 30, 60, 90, dan 120 detik. Empat model unsupervised learning dilatih dan dibandingkan menggunakan Amazon SageMaker dengan pendekatan Bring Your Own Model (BYOM), yaitu Isolation Forest (IF), Local Outlier Factor (LOF), One-Class SVM (OCSVM), dan Autoencoder (AE). Hasil pengujian menunjukkan bahwa Isolation Forest dengan skenario LOG+FE pada time window 60 detik merupakan konfigurasi terbaik dengan nilai precision sebesar 0,938 pada kondisi individu dan 0,643 pada skenario kolaborasi. Autoencoder mencatat waktu inferensi tercepat, sementara LOF menunjukkan performa paling rendah pada seluruh skenario. Analisis distribusi mengungkapkan adanya concept shift pada skenario kolaborasi yang berdampak pada peningkatan False Positive, terutama pada model berbasis densitas.
====================================================================================================================================
Web access logs record user interactions with a system, including request patterns that may indicate attacks such as brute-force attempts, scanning activities, and endpoint exploitation. Since log data are typically large-scale, unstructured, and unlabeled, unsupervised anomaly detection is well suited for identifying abnormal behavior without manual labeling. However, cross-organizational collaboration is often limited by data privacy concerns. This study utilizes AWS Clean Rooms as a privacy-preserving analytics environment that enables collaboration without exposing raw data. The preprocessing stage applies aggregated feature engineering using four feature transformation scenarios: Original (ORI), Feature Engineering (FE), Logarithmic (LOG), and LOG+FE, along with four time-window configurations of 30, 60, 90, and 120 seconds. Four unsupervised learning models were trained and evaluated in Amazon SageMaker using a Bring Your Own Model (BYOM) approach: Isolation Forest (IF), Local Outlier Factor (LOF), One-Class SVM (OCSVM), and Autoencoder (AE). The results show that Isolation Forest with the LOG+FE configuration and a 60-second time window achieved the best performance, with precision scores of 0.938 in the individual setting and 0.643 in the collaborative setting. Autoencoder achieved the fastest inference time, while LOF consistently showed the lowest performance. Further analysis revealed a concept shift in the collaborative setting, leading to increased False Positives, particularly for density-based models.

Item Type: Thesis (Other)
Uncontrolled Keywords: Anomaly Detection, Web Server Log, Aggregated Feature Engineering, AWS Clean Rooms
Subjects: Q Science > QA Mathematics > QA336 Artificial Intelligence
Q Science > QA Mathematics > QA76.585 Cloud computing. Mobile computing.
Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science)
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis
Depositing User: Aditya Situmorang
Date Deposited: 22 Jul 2026 08:45
Last Modified: 22 Jul 2026 08:45
URI: http://repository.its.ac.id/id/eprint/136437

Actions (login required)

View Item View Item