Slamet Triyanto
Kominfo Kab. Kampar

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Pemetaan dan Analisis Permukaan Serangan (Attack Surface) Sistem Elektronik Pemerintah Daerah Melalui Identifikasi Subdomain Resmi Slamet Triyanto; Safni Marwa; Andri Nofiar. Am
Jurnal Elektronika dan Teknik Informatika TerapanĀ ( JENTIKĀ ) Vol. 4 No. 1 (2026): Maret: Jurnal Elektronika dan Teknik Informatika Terapan (JENTIK)
Publisher : Politeknik Kampar

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59061/jentik.v4i1.1386

Abstract

The number of cyberattack incidents recorded by the Badan Siber dan Sandi Negara (BSSN) reached 3.64 million by mid-2025. The majority of these incidents targeted government systems. As of June 2023, Riau Province, which comprises 12 regencies and municipalities, recorded the highest number of incidents among governmental institutions in Indonesia, totaling 54,313,225 cases. The results of domain and subdomain scanning conducted across Riau Province and its regencies/municipalities identified 5,252 public electronic systems. Among these, a significant portion consisted of inactive domains or parking domains, installer pages, landing pages, expired SSL certificates, development pages, and systems potentially utilizing outdated technologies. Although the use of obsolete technologies cannot be conclusively confirmed, this indication is reflected in the number of domains and subdomains affected by web defacement incidents.To ensure that the research process did not violate applicable legal and ethical standards, domain and subdomain scanning and examination were conducted exclusively using publicly available tools, such as web browsers and Subfinder. Furthermore, no deeper penetration testing was performed on the identified findings. This limitation justifies the unavailability of definitive information regarding the use of outdated systems. Finally, asset identification constitutes a crucial stage, enabling the implementation of further measures for incident handling and mitigation efforts aimed at preventing future cyber incidents.