Claim Missing Document
Check
Articles

Found 17 Documents
Search

Implementation of a Supply chain Management System Blockchain-Based in Red Onion Farming Mira Nabila; Farrikh Alzami; Rama Aria Megantara; Fikri Firdaus Tananto; Hasan Aminda Syafrudin; L. Budi Handoko; Chaerul Umam
Jurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi) Vol 11 No 1 (2023): Vol. 11, No. 1, April 2023
Publisher : Lembaga Penelitian dan Pengabdian kepada Masyarakat Universitas Udayana

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24843/JIM.2023.v11.i01.p02

Abstract

Red Onions are a horticultural commodity belonging to the spice vegetable group and an important role for economy of the Indonesian people. In red onion farming there have a problem of price fluctuations which result in an uneven and less transparent distribution of red onions yields, thus affecting both consumers and producers. To answer these problems, we designed a system to maintain and store red onion harvest data for farmers, collectors, distributors, and retailers in the form of a blockchain-based supply chain system. This system can maintain the validity of transactions in the supply chain of red onion farming with a private blockchain with Hyperledger Fabric. Then the data on the blockchain system will be displayed through the Hyperledger Explorer website. This system already passed the Black Box Testing system. From the research and testing of the system that has been made, this system can help the red onion farming to maintain the validity of transactions in the supply chain management.
Kombinasi Steganografi LSB dan Kriptografi AES dalam Sekuriti Teks Rahasia Pada Citra Berwarna Chaerul Umam; Muslih Muslih; Daffa Fadillah
Seminar Nasional Teknologi dan Multidisiplin Ilmu (SEMNASTEKMU) Vol 2 No 1 (2022): SEMNASTEKMU
Publisher : Universitas Sains dan Teknologi Komputer

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.51903/semnastekmu.v2i1.160

Abstract

Ketergantungan terhadap teknologi sebagai alat untuk melakukan dan membantu manusia dalam mengerjakanbanyak hal dan instan, membuat penggunaan teknologi menjadi semakin massif dan seringkali terjadipenyalahgunaan terhadap teknologi. Penggunaan yang massif dalam skala besar-besaran dan tidak terkontrolmembuat teknologi menjadi media yang rawan akan tindakan kriminal dan illegal. Faktor keamanan data menjadisuatu hal yang sangat penting dan harus dipertimbangkan terkait dengan semakin tingginya tingkat pertukaran data.Oleh sebab itu penulis memiliki gagasan dalam pengamanan data dengan menggabungkan teknologi kriptografi dansteganografi. Pemanfaatan algoritma kriptografi Advanced Encryption Standard dan steganografi Least SignificantBit diharapkan mampu untuk membantu dalam pengamanan data di era saat ini.
Comparative Analysis of TinyBERT, SVM, and Char-CNN Models for Phishing URL Detection Haeranisa Bella Krisanti; Chaerul Umam
SISTEMASI Vol 15, No 5 (2026): Sistemasi: Jurnal Sistem Informasi
Publisher : Universitas Islam Indragiri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.32520/stmsi.v15i5.6345

Abstract

Phishing is one of the most prevalent cybersecurity threats that exploits malicious URLs to deceive users and steal sensitive information. This study proposes a URL-based phishing detection method using the lightweight Transformer model TinyBERT and compares its performance with three baseline models: SVM based on character n-grams, Random Forest based on lexical URL features, and Char-CNN. The dataset used in this study consists of 49,750 URLs with multi-class labels (benign, defacement, malware, and phishing), which were subsequently binarized into phishing (label 1) and non-phishing (label 0). The data were divided using a stratified split into training, validation, and testing sets with a ratio of 70%–15%–15%. To address class imbalance, the TinyBERT model was trained using a weighted loss approach based on class weights. The evaluation was conducted using a confusion matrix, accuracy, precision, recall, F1-score, as well as ROC and Precision–Recall curves. Experimental results demonstrate that TinyBERT achieved the best performance, with an accuracy of 0.9925, phishing recall of 0.9512, and an F1-score of 0.9387. In addition, the model produced the lowest number of false negatives (22) compared with the baseline models. These findings indicate that TinyBERT is more effective in minimizing phishing URLs that are incorrectly classified as benign, making it more suitable for implementing URL-based phishing detection in cybersecurity systems.
Analisis Keamanan Sistem Keuangan Daerah Menggunakan Black Box Penetration Testing Muhammad Addissahhilna; Chaerul Umam
Jurnal Algoritma Vol 23 No 1 (2026): Jurnal Algoritma
Publisher : Institut Teknologi Garut

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.33364/algoritma/v.23-1.3120

Abstract

Information system security is a crucial aspect in supporting digital-based regional financial services. This study offers novelty by implementing penetration testing on the financial service system of Pati Regency, which previously had not been comprehensively evaluated. The black-box testing method is used to simulate external attacks, while the Penetration Testing Execution Standard (PTES) is selected because it provides structured and replicable work stages, thereby improving the accuracy of vulnerability identification. The testing results reveal serious vulnerabilities, such as exposure of the phpinfo() page and the use of default credentials in the login process, which are classified as high risk based on CVSS 3.1. These vulnerabilities had not been detected by the system administrators prior to testing. The implementation of security recommendations, including brute-force protection, removal of sensitive pages, and strengthened authentication mechanisms, is able to significantly reduce the level of risk. The main contribution of this research lies in providing a structured and applicable security evaluation model for local governments to enhance the resilience of digital financial services against cyberattacks.
Analisis Keamanan Website UPT RSUD RAA Soewondo Pati Berdasarkan Hasil Penetration Testing Menggunakan Owasp Dani Yudanta Prapaskia; Chaerul Umam
Jurnal Algoritma Vol 23 No 1 (2026): Jurnal Algoritma
Publisher : Institut Teknologi Garut

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.33364/algoritma/v.23-1.3429

Abstract

The development of technology in the healthcare sector has encouraged the utilization of web-based platforms to comprehensively support hospital service operations. This requires the implementation of strict security standards to protect the privacy of patients’ medical data. This study focuses on evaluating the security level of the official website of UPT RSUD RAA Soewondo Pati through penetration testing based on the OWASP framework. The evaluation stages included web infrastructure identification using Wappalyzer and vulnerability scanning using OWASP ZAP. Based on the testing results, several security vulnerabilities with varying levels of risk were identified, including SQL Injection, Cross-Site Scripting (XSS) threats, and vulnerabilities related to session management and authentication systems. In general, the system’s security profile falls into the medium-risk category, indicating that further improvements are required to reduce cyber threats. The use of OWASP guidelines in this study proved effective in identifying system weaknesses while also formulating mitigation strategies, such as optimizing server configuration, implementing secure coding practices, and improving authentication workflows.
Vulnerability Analysis on Semarang City Road Section Information System Website Using VAPT Method Hanif Setia Nusantara; L. Budi Handoko; Maulana Ikhsan; Chaerul Umam
Journal of Innovation and Technology Polbeng Series on Informatics (INOVTEK Polbeng - Seri Informatika) Vol. 10 No. 2 (2025): July
Publisher : P3M Politeknik Negeri Bengkalis

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35314/gdaky847

Abstract

Web-based public service applications in the digital governance era are increasingly vulnerable to cyber threats. This study analyzes the vulnerability of the Semarang City Road Information System website quantitatively using the Vulnerability Assessment and Penetration Testing (VAPT) method to evaluate its effectiveness in identifying security gaps. This system is part of an e-government service providing road infrastructure information but, like other technology-based systems, is susceptible to exploitation. The VAPT method used includes two main stages: Vulnerability Assessment to identify weaknesses and Penetration Testing to simulate attacks. The study identified 5 potential vulnerabilities: SQL Injection, Credit Card Number Disclosure, Insecure Direct Object Reference (IDOR), Cross-Site Scripting (XSS), and Error Message on Page. However, 80% of these were false positives, effectively filtered by Alibaba Cloud’s Web Application Firewall (WAF). The IDOR vulnerability was confirmed as valid, allowing unauthorized access to sensitive data through manipulation of the ID parameter in the URL. The original contribution of this research is the specific recommendation for implementing Indirect Object References mechanisms such as ID encryption, as well as emphasizing the need for comprehensive routine testing to improve security and prevent potential data misuse.
DETEKSI DAN MITIGASI SERANGAN POST-EXPLOITATION PADA LINGKUNGAN CONTAINER LINUX MENGGUNAKAN CROWDSEC DAN AUDITD Julang Tahta Pratangga; Chaerul Umam; L. Budi Handoko; Wildanil Ghozi
Rabit : Jurnal Teknologi dan Sistem Informasi Univrab Vol 11 No 2 (2026): Juli
Publisher : LPPM Universitas Abdurrab

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.36341/rabit.v11i2.8461

Abstract

Containerized environments present significant security challenges due to their shared kernel architecture, which may be exploited as an entry point for infiltration attacks. One common vulnerability is Command Injection, enabling post-exploitation activities that are difficult to detect using conventional signature-based mechanisms. This study aims to implement and evaluate an active mitigation mechanism based on behavioral analysis by integrating the Linux Audit Daemon (Auditd) and CrowdSec within a Podman container environment. The research adopts an Experimental Security Testing approach by developing a Custom Process Bouncer that specifically monitors the execve system call to identify process relationships and automatically terminate malicious processes. Test results against four detection scenarios demonstrate that the proposed mechanism successfully reconstructed the attack process chain through PID cascade analysis and detected six malicious processes generated during the Command Injection scenario. All identified processes were automatically terminated with precision, causing the reverse shell session to be interrupted. These findings conclude that the integration of Auditd, CrowdSec, and the Custom Process Bouncer effectively neutralizes post-exploitation activities reliant on binary file execution, though further development is required to address fileless execution tactics.