Automated Cyberattack Response System: A Combination of AI and Human Control with Recommendations for Measurable Actions

Authors

  • Febrian Sulistyo Budi UNIVERSITAS DUTA BANGSA SURAKARTA
  • Bondan Wahyu Pamekas UNIVERSITAS DUTA BANGSA SURAKARTA
  • Arif Setiawan UNIVERSITAS DUTA BANGSA SURAKARTA

DOI:

https://doi.org/10.32664/46rn3x55

Keywords:

SIEM, Wazuh, LLM, Incident Response, MTTR, n8n

Abstract

The growing frequency and complexity of cyberattacks have placed significant pressure on the security of digital infrastructure, particularly because manual incident handling tends to be slow and prone to delayed responses. This study aims to design and build an automated security incident response system that combines artificial intelligence with human oversight to improve both the speed and quality of response. The system was developed using the Waterfall method, integrating Wazuh as the network security monitoring platform, n8n as the workflow orchestration engine, and the Llama 3.1 8B language model accessed through the Groq API to generate mitigation recommendations in plain, easy-to-understand language. A human-in-the-loop approval mechanism was implemented through a Telegram bot, requiring analyst confirmation before any mitigation action is executed. The system was evaluated across three attack scenarios, SSH brute force, multiple failed login attempts, and suspicious file modification, each tested 15 times in a controlled virtual environment. The results show an average response time of 21.2, 34.1, and 36.3 seconds for each scenario respectively, far outperforming manual handling, which typically requires between 600 and 1,800 seconds. This translates into a response speed improvement of up to 98%, while the AI-generated recommendations remained fully consistent with the rule-based engine across all 45 trials conducted. These findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.

Downloads

Published

2026-07-25

Issue

Section

Articles