Claim Missing Document
Check
Articles

Found 3 Documents
Search

Manajemen Risiko Serangan Siber Menggunakan Framework NIST Cybersecurity Tony Tan; Benfano Soewito
JISAMAR (Journal of Information System, Applied, Management, Accounting and Research) Vol 6 No 2 (2022): JISAMAR: May 2022
Publisher : Sekolah Tinggi Manajemen Informatika dan Komputer Jayakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.52362/jisamar.v6i2.781

Abstract

Pendidikan tinggi pada saat ini telah menggunakan sistem teknologi informasi seperti sistem layanan berbasis web dan situs web sebagai sarana untuk mendukung pelaksanaan pendidikan. Oleh karena itu, sistem teknologi informasi yang terdapat pada kampus harus terjaga keamanan dan ketahanannya guna untuk memberikan pelayanan yang terbaik untuk dosen, staf, dan mahasiswa. Tidak menutup kemungkinan, sistem teknologi informasi yang terdapat pada kampus memiliki cela peretasan yang bisa dimasuki oleh penjahat dunia maya atau hacker. Oleh karena itu, perlu adanya metode untuk meningkatkan keamanannya. Dalam studi ini, kami menguji keamanan siber pada Universitas ZXC dengan menggunakan Framework NIST Cybersecurity. Pengambilan data dilakukan dengan cara wawancara, studi dokumentasi insiden, dan observasi. Penilaian terhadap 39 sistem layanan web dan situs web. Penulis juga menggunakan aplikasi Nessus untuk menilai cela dan tingkat ancaman. Hasil dari penilaian menunjukan hasil kondisi keamanan siber di lingkungan Universitas ZXC masih belum mencapai standar yang direkomendasikan. Hal serupa juga ditunjukan melalui hasil penilaian aplikasi Nessus yang menunjukan kondisi cela pada sistem layanan web dan situs web yang cukup banyak. Dari hasil penelitian ini, kami memberikan rekomendasi control menggunakan Framework NIST Cybersecurity untuk meningkatkan keamanan siber pada sistem layanan web dan situs web.
Analisis Keamanan Infrastruktur Jaringan Berdasarkan Cyber Kill Chain Framework Utama Hasiolan Panggabean; Benfano Soewito
JUSIFO : Jurnal Sistem Informasi Vol 9 No 1 (2023): June
Publisher : Program Studi Sistem Informasi, Fakultas Sains dan Teknologi, Universitas Islam Negeri Raden Fatah Palembang

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.19109/jusifo.v9i1.17365

Abstract

This study concentrates on examining the security of network infrastructure using the cyber kill chain framework approach. The research is conducted within a company operating in network security services. In its operations, it offers a Virtual Private Cloud (VPC) containing various crucial information such as applications, internal data, client data, and product demos. Despite the attractive features of cloud computing, there are significant threats as well. Handling attacks cannot be swiftly and efficiently executed, resulting in temporary operational unavailability until the attacks are resolved. This research delves into the security of the company's infrastructure by testing several points of vulnerability exploited by malicious parties. The cyber kill chain framework approach is employed to systematically assess the company's infrastructure. The study reveals that certain issues have been adequately detected; however, security gaps persist, as evidenced by the testing conducted and the inadequate response from the company's security systems.
Security Assessment Based on OWASP Top 10 Using SonarQube and ZAP on Export and Import Applications in the LNSW Muhammad Wisnu; Benfano Soewito
INTENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi Vol 10 No 1 (2026)
Publisher : Universitas Nusantara PGRI Kediri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29407/intensif.v10i1.25294

Abstract

Background: The advancement of information and electronic systems has significantly transformed export and import processes. In Indonesia, the Lembaga National Single Window (LNSW) plays a pivotal role in facilitating international trade by integrating procedures and information related to exports, imports, and document flows. Objective: This study aims to assess the security of LNSW’s export and import application by identifying vulnerabilities based on the Open Web Application Security Project (OWASP) Top 10 framework. It also compares the effectiveness of Static Application Security Testing (SAST) using SonarQube and Dynamic Application Security Testing (DAST) using ZAP (Zed Attack Proxy) in detecting various types of vulnerabilities. Methods: The analysis involved the use of SonarQube for source code scanning and ZAP for runtime testing. Each detected vulnerability was evaluated using the Common Vulnerability Scoring System (CVSS) to determine its severity level. Recommended mitigation strategies were provided accordingly. Results: A total of eight vulnerabilities were identified, comprising two High-severity and six Medium-severity issues. SonarQube proved more effective in detecting Identification and Authentication Failures (three instances), while ZAP excelled in identifying Vulnerable and Outdated Components (two instances). Notably, each tool uncovered four unique types of vulnerabilities that the other did not detect. Conclusion: These findings highlight the practical benefits of combining SAST and DAST techniques. By integrating both approaches, organizations can achieve a more comprehensive and reliable security assessment, ultimately leading to more resilient software systems.