Claim Missing Document
Check
Articles

Found 3 Documents
Search

Identifikasi Bukti Digital pada Akuisisi Perangkat Mobile dari Aplikasi Pesan Instan “WhatsApp” Ayubi Wirara; Bangkit Hardiawan; Muhammad Salman
Teknoin Vol. 26 No. 1 (2020)
Publisher : Faculty of Industrial Technology Universitas Islam Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.20885/teknoin.vol26.iss1.art7

Abstract

Aplikasi pesan instan menjadi salah satu alasan utama untuk seorang pengguna menggunakan internet. Saat ini WhatsApp menjadi aplikasi pesan instan dengan pengguna terbesar di indonesia karena beragam fitur yang telah didukung. Hal ini tentu saja membuat WhatsApp bukan hanya digunakan untuk bertukar informasi biasa tapi juga informasi terkait kasus kejahatan. Sehingga bukti digital aplikasi pesan instan WhatsApp pada smartphone menjadi potensial dalam berbagai kasus kriminal dan proses persidangan. Pada penelitian ini dilakukan analisis terhadap bukti digital whatsapp yang dapat diperoleh dalam proses akuisisi perangkat smartphone. Target perangkat yang diakuisisi pada penelitian ini adalah smartphone berbasis android dan iOS. Hasil ekstraksi didapatkan beberapa bukti digital aplikasi WhatsApp yang berhasil didapatkan meskipun perangkat tidak dilakukan proses root/jailbreak terlebih dahulu.
Validation of the Harmonized Mobile Forensic Investigation Process Model (HMFIPM) on Android Devices Mutia Aziza; Muhammad Salman
Equivalent: Jurnal Ilmiah Sosial Teknik Vol. 8 No. 2 (2026): Equivalent: Jurnal Ilmiah Sosial Teknik
Publisher : Politeknik Siber Cerdika Internasional

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59261/jequi.v8i2.320

Abstract

Background: The increasing use of smartphones has been accompanied by the growing misuse of mobile devices in cybercrime, making mobile forensics essential for identifying, acquiring, recovering, and analyzing digital evidence. However, standardized mobile forensic investigation models for field implementation remain limited. The Harmonized Mobile Forensic Investigation Process Model (HMFIPM) has been proposed as a structured investigation model, but its empirical implementation in an accredited forensic laboratory environment remains underexplored. Objective: This study aims to empirically validate the implementation of HMFIPM as a structured process model for Android mobile forensic investigations within an ISO/IEC 17025-accredited Digital Forensics Laboratory. Methods: This study applied a descriptive and implementation-based approach. Descriptive analysis was conducted through examiner interviews, while implementation analysis was performed by applying the HMFIPM stages to a Samsung SM-A075F device using Full File System extraction with Cellebrite UFED and Android Live extraction with MD. Results: All HMFIPM stages were successfully implemented and mapped to the mobile forensic workflow in the laboratory environment. The model supported a structured, documented, and evaluable investigation process. Differences in artifact recovery were primarily caused by tool-to-method compatibility and application data architecture rather than by limitations of the HMFIPM model. Cellebrite UFED using Full File System acquisition produced more complete artifacts, while MD using Android Live extraction obtained partial application artifacts. Conclusion: HMFIPM is feasible as a standardized framework for Android mobile forensic investigation. However, the feedback mechanism requires refinement. This study proposes an additional data acquisition feedback path alongside the existing analysis feedback path, allowing examiners to revisit the acquisition stage when new investigative needs arise.
A Comparative Effectiveness Analysis of Signature-Based IDS and Network Detection and Response (NDR) in a SIEM Environment Christian Hary; Muhammad Salman
Jurnal Locus Penelitian dan Pengabdian Vol. 5 No. 8 (2026): JURNAL LOCUS: Penelitian dan Pengabdian
Publisher : Riviera Publishing

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58344/locus.v5i8.5976

Abstract

As cyber threats increasingly employ cryptographically concealed and stealthy communication, traditional signature-based Network Intrusion Detection Systems (NIDS) encounter severe limitations in achieving end-to-end operational visibility. This study delivers a quantitative comparative analysis contrasting signature-based frameworks against metadata-driven Network Detection and Response (NDR) within a unified Security Information and Event Management (SIEM) platform. Configured with a massive ruleset of 47,192 active signatures, the NIDS engine was evaluated against the behavioral metadata abstraction of NDR across five structured attack scenarios mapping the Cyber Kill Chain. Experimental results reveal a critical Visibility Gap in post-exploitation defenses; while NIDS achieved a 60\% Detection Rate by intercepting noisy initial reconnaissance and exploit payloads, it suffered total blindness during post-exploitation maneuvers. Conversely, the NDR engine achieved a 100\% Detection Rate, isolating deterministic forensic indicators including a 716.33-second encrypted command and control (C2) session and a 7.07 MB volumetric data exfiltration burst. Furthermore, architectural benchmarking revealed that massive rule compilation induced structural management plane synchronization failures. These findings synthesize into validated recommendations for sensor optimization, establishing an operational framework for specialized role allocation and computational efficiency to eliminate visibility blind spots within enterprise Security Operations Center (SOC) environments.