Claim Missing Document
Check
Articles

Found 28 Documents
Search

Implementasi Dashboard Monitoring untuk Pengujian Kerentanan SQL Injection pada Environment GitLab Azhar, Muhammad Fahmi Al; Harwahyu, Ruki
Smart Comp :Jurnalnya Orang Pintar Komputer Vol 12, No 3 (2023): Smart Comp: Jurnalnya Orang Pintar Komputer
Publisher : Politeknik Harapan Bersama

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30591/smartcomp.v12i3.5492

Abstract

SQL Injection masih menjadi salah satu jenis kerentanan yang paling sering ditemukan pada aplikasi berbasis web. Pengujian terhadap aplikasi sebelum dirilis ke production harus dilakukan semaksimal mungkin agar kerentanan ini tidak muncul saat aplikasi tersebut rilis ke production. Salah satu jenis pengujian yang harus dilakukan adalah Static Application Security Testing (SAST). SAST bekerja dengan cara memindai dan menganalisis seluruh source code di dalam project untuk diperiksa apakah terdapat kesalahan logika dan jenis kerentanan tertentu. Dengan menggunakan platform GitLab, pengujian dapat dilakukan secara otomatis. Namun, hasil dari pengujian SAST tersebut tidak dapat dilihat secara langsung melalui platform GitLab. Berdasarkan kondisi tersebut, maka dibutuhkan aplikasi dashboard monitoring yang dapat diakses oleh tim pengembang dan tim operasional TI. Dengan menggunakan dashboard ini, maka programmer dapat mengetahui bagian source code mana yang mengandung kerentanan SQL Injection. Dashboard ini dibuat dengan menggunakan framework PHP CodeIgniter 4 dan Database MySQL.
Analisis Dan Verifikasi Protokol Kriptografi Aplikasi Manajemen Kunci Menggunakan Scyther: Studi Kasus Aplikasi XYZ Nurdiyanto, Indra Dimas; Harwahyu, Ruki
Smart Comp :Jurnalnya Orang Pintar Komputer Vol 12, No 2 (2023): Smart Comp: Jurnalnya Orang Pintar Komputer
Publisher : Politeknik Harapan Bersama

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30591/smartcomp.v12i2.5293

Abstract

Semakin meningkatnya ancaman dan serangan yang mengakibatkan kebocoran data di Indonesia sejalan dengan pesatnya perkembangan teknologi dan informasi.   Menjawab tantangan tersebut instansi ABC mengembangkan aplikasi XYZ sebagai salah satu solusi dalam pengamanan data dan informasi. Oleh karena itu, untuk memastikan kemampuan aplikasi tersebut dalam memberikan jaminan keamanan kepada pengguna, pada penelitian ini dilakukan analisis dan verifikasi keamanan protokol kriptografi aplikasi XYZ. Analisis dan verifikasi dilakukan melalui pendekatan verifikasi formal menggunakan alat bantu Scyther dengan focus pada protokol verifikasi pengguna, pembangkitan kunci, dan permintaan kunci untuk proses enkripsi-dekripsi. Hasil analisis menunjukan bahwa protokol-protokol tersebut telah menenuhi kriteria secrecy untuk informasi rahasia yang ditransmisikan namun memiliki kelemahan pada aspek autentikasi. Penerapan sharedsecret dan rangkaian cryptographic nonce terbukti  mampu mengatasi kelemahan pada protokol verifikasi pengguna aplikasi XYZ.
Implementation Strategy Analysis of Network Security using dalo RADIUS and Pi-hole DNS Server to enhance Computer Network Security, Case Study: XYZ as a Fintech Company Andika Davi Yudhistira; Ruki Harwahyu
Jurnal Indonesia Sosial Teknologi Vol. 5 No. 10 (2024): Jurnal Indonesia Sosial Teknologi
Publisher : Publikasi Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59141/jist.v5i10.5321

Abstract

According to the annual report by the National Encryption Agency in 2023, Indonesia had the highest number of cyber-attack sources, with over 1 million attacks, which has increased quite rapidly compared to the last 3 years. Several online media platforms have reported incidents of this nature over the past three years. Among the 10 institutions implicated in the present incident, it has been confirmed that 6 of them are Fintech institutions. The incident's factors are various, including the user's lack of awareness who accessed an unofficial website outside the company's production website. This act ultimately proved to be detrimental to the company. Therefore, this study highlights the importance of RADIUS (Remote Authentication Dial-In User Service) as a comprehensive security tool that contributes to mitigating unauthorized access and strengthening network defenses against emerging threats. This research focuses on XYZ, a Fintech Company, using it as a case study. The main discussion in this paper focuses on utilizing the daloRADIUS server to resolve authorization concerns regarding network security. Pi-hole DNS Server is also used in this research to block access to illegal sites such as pornography and online gambling. The results of this research are proof of the success of a combination of daloRADIUS server components, RADIUS router, and Pi-hole DNS Server in blocking users who are detected accessing illegal sites and are also observed regarding the use of daloRADIUS Server resources in a usage range ranging from 10 active users to 300 active users.
A Tamper-Evident Audit Logging Framework for Decentralized Single Sign-On: Prototype Design and Evaluation in Education-Oriented Digital Services Yufan Amri; Ruki Harwahyu
Journal of Vocational, Informatics and Computer Education Vol 4, No 1 (2026): March 2026
Publisher : Academic Bright Collaboration

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.66053/voice.v4i1.479

Abstract

Purpose – This study aims to design, implement, and evaluate a prototype framework for tamper-evident audit logging in a decentralized single sign-on environment for education-oriented digital services. It addresses the risk that detailed authentication and session records remain stored in mutable off-chain systems, while storing complete audit data on-chain may increase costs and privacy exposure. Methods – The study adopted an artifact-based prototype design and evaluation approach. The prototype combined PostgreSQL-based off-chain audit storage, deterministic snapshot construction, canonical JSON serialization, SHA-256 hashing, Merkle root generation, and blockchain anchoring through the AuditAnchor smart contract on the Polygon Amoy testnet. The evaluation was conducted in a controlled prototype environment through tamper-detection testing, latency benchmarking, snapshot and proof performance measurements, storage-growth observations, and anchoring cost analysis. Findings – Post-anchoring record modification, deletion, and insertion consistently produce root mismatches. Across the evaluated workloads, snapshot construction remained below 0.4 s for up to 5,000 records, proof verification remained lightweight, and anchoring consumed 49,953 gas per transaction under the tested setup. Research implications – The prototype suggests that education-oriented multi-service environments may benefit from keeping detailed audit data off-chain while anchoring compact integrity commitments on-chain to support audit reviews, cross-service access tracing, and post-incident verifications. Originality – This study contributes a prototype-level integration of decentralized SSO, deterministic off-chain audit snapshots, and on-chain Merkle-root anchoring for audit verification
Integrating the DeepSeek-R1 model as an analytical assistant in digital forensic investigations of corruption cases Hafni Ferdian; Ruki Harwahyu
Integritas: Jurnal Antikorupsi Vol 11 No 2 (2025): INTEGRITAS: Jurnal Antikorupsi
Publisher : Komisi Pemberantasan Korupsi

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.32697/integritas.v11i2.1557

Abstract

This article examines the integration of the DeepSeek-R1 large language model as an analytical assistant in digital forensic investigations, particularly in corruption cases. The growing volume of digital evidence often leads to substantial analysis backlogs that can extend for months or even years, thereby hindering law enforcement efforts [1]. The use of Artificial Intelligence (AI) and Large Language Models (LLMs) offers the potential to improve investigative efficiency by reducing the burden of processing massive datasets. DeepSeek-R1 is a newly released open-source LLM with advanced reasoning capabilities, achieving performance comparable to state-of-the-art models developed by OpenAI. This study outlines the role of DeepSeek-R1 in supporting digital forensic workflows—from tracing electronic evidence and analyzing data relationships to generating preliminary investigative reports. The methodology includes simulated corruption case experiments comparing investigations assisted by DeepSeek-R1 with conventional manual analysis. The results show that DeepSeek-R1 can accelerate the retrieval of relevant information and produce concise summaries rapidly, significantly reducing analysis time. However, the model remains prone to factual errors (hallucinations) and biases, making human validation by investigators essential. With proper risk mitigation and oversight, integrating DeepSeek-R1 has the potential to significantly enhance the effectiveness of digital forensic investigations in combating corruption.  
A Formally Specified Extension of RFC 9411 Benchmark Methodology for Sandbox-Based Advanced Threat Prevention in Next-Generation Firewalls Risqi Khoirun Nisa; Ruki Harwahyu
Journal of Vocational, Informatics and Computer Education Vol 4, No 2 (2026): June 2026
Publisher : Academic Bright Collaboration

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.66053/voice.v4i2.892

Abstract

Purpose – This study proposes a formally specified, composable extension of RFC 9411 for benchmarking sandbox-based advanced threat prevention (ATP) in next-generation firewalls (NGFWs). It addresses four properties that the current standard cannot characterize: asynchronous verdict generation, file-level inspection granularity, bypass behavior under overload, and verdict latency as a security efficacy dimension.Methods – Following a design science methodology, the study develops a framework comprising a test traffic profile parameterized by file arrival rate (F), size distribution (s), type distribution (t), and maliciousness ratio (m); five formally defined key performance indicators (KPIs); a mapping table relating each component to its RFC 9411 counterpart; and a three-phase test procedure covering steady-state, overload, and recovery conditions. Empirical need is established through a vendor disclosure survey across three leading enterprise NGFW product lines.Findings – An illustrative scenario application, using plausible values rather than instrumented measurements, shows how the proposed KPIs would expose behaviors invisible to RFC 9411, such as a policy-driven bypass of 14% under a 30% traffic overload and a quantifiable trade-off between detection rate (α = 0.91–0.96) and verdict latency (p50 = 18–47 s). Empirically, a disclosure survey of three enterprise NGFW datasheets finds all five sandbox-specific KPIs absent from every datasheet, with composite disclosure indices of 23–34% and a cross-vendor mean of 28%. Research implications – The framework enables reproducible, comparable sandbox benchmarking and provides a normative basis for SLA design, evidence-based procurement, and IETF BMWG standardization.Originality – This study contributes the first formally specified, RFC 9411-composable benchmarking layer for sandbox-based ATP, introducing five new KPIs with mathematical definitions and a composability mapping table.
Rethinking Classroom Ventilation in post pandemic Situation Ruki Harwahyu; Hastin Setiani; Muhammad Surya Faroghi; Riri Fitri Sari
Journal of Sustainability Perspectives Vol 2, No 2 (2022)
Publisher : Universitas Diponegoro

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (304.841 KB) | DOI: 10.14710/jsp.2022.15479

Abstract

This paper aims to contribute in outlining the latest findings and formulating a simple practice in providing sufficient air circulation for classroom activities in preparation for the post-pandemic era. During this pandemic, remote learning over the internet has been a viable solution everywhere, including adopted by education institution to keep serving the learning process. However, as more and more people involved and the time elapses, several disadvantages of e-learning are realized. In addition, education institution should be prepared for the upcoming offline learning activity in post-pandemic era. This paper aims to refine the minimum airflow requirement for the classroom, finetuned based on student activity, ceiling height. Student activity is being the focus rather than teacher because student represents the majority of classroom occupant. In addition, a discussion on how it can be achieved using simpler ventilation system is presented. ON/OFF scheme for the usage of the active ventilation is also elaborated.Keyword: classroom, post-pandemic era, ventilation system, air circulation.
Comparative Evaluation of Mobile Forensic Acquisition Methods on iOS 17: A Study of Cellebrite Basic and Premium in Digital Artifact Recovery Ghifari Amanar; Ruki Harwahyu
Journal of Business, Social and Technology Vol. 7 No. 3 (2026): Journal of Business, Social and Technology
Publisher : Politeknik Siber Cerdika Internasional

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59261/jbt.v7i3.706

Abstract

Background: The advancement of security systems in modern smartphones, particularly iOS devices, has introduced significant challenges to digital forensic investigations. At the same time, law enforcement agencies increasingly rely on digital evidence, making the completeness and reliability of acquisition methods critical factors in forensic examinations. Objective: This study aims to evaluate the differences in the completeness of digital artifacts obtained through logical acquisition and full file system (FFS) extraction methods on an iPhone 13 running the latest iOS version. Methods: An experimental methodology was employed by developing a ground-truth dataset based on user activity scenarios, including communications, media exchanges, and application usage. The acquisition results were subsequently analyzed to measure the recovery rate of digital artifacts, including deleted data and application-related artifacts. Results: The findings indicate that the FFS extraction method is capable of recovering a more comprehensive set of artifacts than logical acquisition, particularly data that cannot be accessed through conventional methods. However, this method involves greater complexity and depends on advanced forensic tools. Specifically, the FFS method recovered 64,057 files compared to 959 files obtained through Advanced Logical Extraction, representing a 6,580% increase in artifact volume. Notable differences were observed in web history (1,466 vs. 43 entries), images (13,140 vs. 367 files), and database artifacts (997 vs. 188 records). Conclusion: This research highlights the importance of selecting appropriate acquisition methods to support investigative processes and legal evidence examination, while also identifying a research gap in the forensic evaluation of devices running the latest versions of iOS.