Hermes-Based Agentic Security Response System for Log Anomaly Detection and Limited Mitigation

Authors

  • Surya Tri Atmaja Ramadhani Universitas Amikom Yogyakarta
  • Fiyas Mahananing Puri
  • Vikky Aprelia Windarni
  • Dewi Anisa Istiqomah
  • Efrat Tegris

DOI:

https://doi.org/10.35842/ijicom.v8i2.268

Keywords:

Hermes, Log Anomaly Detection, Ubuntu Server, Server, Mitigation

Abstract

Ubuntu Server security depends on timely interpretation of authentication, firewall, and system logs, particularly in the Generative AI era, where security operations increasingly need contextual analysis, triage support, and controlled response recommendations. The problem addressed in this study is that manual log analysis and pattern-based tools can identify explicit indicators, but they provide limited incident reasoning, severity assessment, and playbook-validatable mitigation recommendation. This study proposes and evaluates a Hermes-based agentic security response system as an analysis and response-recommendation support layer, not as a replacement for SIEM, IDS, Fail2Ban, or rule-based detection. The proposed method consists of log collection, preprocessing into structured event groups, Hermes-based classification and contextual reasoning, threat-decision mapping, and playbook-based mitigation validation. The evaluation used a controlled proof-of-concept dataset generated from local simulations, consisting of 404 log records and eight scenario groups. Under this controlled setting, both the rule-based baseline and Hermes achieved accuracy, precision, recall, and F1-score of 1.00, while Hermes also achieved attack type accuracy, severity accuracy, mitigation action accuracy, and reasoning validity rate of 1.00. These findings show that the workflow behaved consistently when it was applied to explicit, well-bounded simulated scenarios. The value of the study therefore lies not in claiming better detection accuracy, but in showing how automated severity triage, attack-type interpretation, contextual reasoning, auditability, and safe limited response recommendation can complement deterministic rule-based approaches.

Downloads

Download data is not yet available.

Downloads

Published

2026-07-16

How to Cite

Ramadhani, S. T. A., Puri, F. M., Windarni, V. A., Istiqomah, D. A., & Tegris, E. (2026). Hermes-Based Agentic Security Response System for Log Anomaly Detection and Limited Mitigation. International Journal of Informatics and Computation, 8(2), 636–652. https://doi.org/10.35842/ijicom.v8i2.268