Claim Missing Document
Check
Articles

Found 28 Documents
Search

Risk Analysis of Bruteforce Attacks on Webserver with Telegram Notifications Budi Wibowo; Luqman Hafiz
Jurnal Komputer dan Elektro Sains Vol. 3 No. 1 (2025): komets
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/komets.v3i1.305

Abstract

In today's digital era, server security is a top priority for many organizations. Intrusion Detection Systems (IDS) such as Fail2ban, have proven effective in protecting servers from threats by monitoring logs and blocking suspicious IP addresses. This paper discusses the implementation of Fail2ban integrated with Telegram notifications, how it works, testing, and results showing improvements in detecting and responding to attacks. Server ssh brute force attacks pose considerable risks to web servers and have potentially severe consequences. Implementing strong preventive measures, continuous monitoring, and leveraging Telegram notifications for real-time alerts significantly improved the organization’s security posture. These combined efforts ensure robust and responsive detection of brute force attacks. Fail2ban was able to quickly discover the IP address from which the attacker performed the brute force attack and took preventive action by blocking the attacker's Ip for 3 failed login attempts within a specified time limit of 3600 s.
Developing a Context-Aware Self-Assessment Model to Mitigate Phishing Vulnerabilities in Academic Institutions Andrie Yuswanto; Budi Wibowo; Taufik Hidayat
Jurnal Komputer dan Elektro Sains Vol. 4 No. 1 (2026): komets
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/komets.v4i1.544

Abstract

Higher education institutions in Indonesia have emerged as primary targets for cyberattacks, particularly phishing, due to the high value of academic data and the inherent openness of information access. Conventional technical security approaches often fail to mitigate human error, which remains a critical vulnerability. This study aims to develop a phishing vulnerability detection model based on active participation (self-assessment) using the WiCanary platform to enable academic communities to measure their security risks independently. Employing a Research and Development (R&D) methodology, contextual phishing simulations were conducted on 100 respondents at the Budi Utomo Institute of Technology. The experimental results revealed an average vulnerability rate (Click Rate) of 22%, contrasted by a low Reporting Rate of only 7%. A significant gap was identified between theoretical knowledge and actual behavior, particularly among faculty members who exhibited the Dunning-Kruger Effect in response to administrative-themed scenarios. However, the implementation of the self-assessment model successfully enhanced knowledge retention and reduced vulnerability by 40% in subsequent testing. In conclusion, this model serves as an effective, persuasive, and sustainable early mitigation strategy to fortify the human firewall within academic environments.
A Review Method for Analysis of the Causes of Data Breach in the Pasca Pandemic Andrie Yuswanto; Budi wibowo; Luqman Hafiz
Jurnal Komputer dan Elektro Sains Vol. 3 No. 1 (2025): komets
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/komets.v3i1.205

Abstract

The vulnerability of personal data breaches makes countries aware of the importance of regulations governing the protection of personal data Therefore, the importance of this research is to conduct a systematic review of the causes of data breaches based on the mechanism of activities carried out to answer problems and provide solutions to problems related to information security. The Systematic Literature Review (SLR) method was used to identify 283 papers in IEEE Xplore database, direct and signature digital science library based on automated search and predefined strings. Then 18 papers were selected for study based on inclusion and exclusion criteria. From the literature study, it can be concluded that the trends analyzed, data breaches are caused by user behavior that has not been educated about the dangers of data theft and awareness of information security.
Social Engineering as a Major Cybersecurity Threat: Analysis of Challenges and Solutions for Organizations Budi Wibowo
International Journal of Science Education and Cultural Studies Vol. 3 No. 2 (2024): ijsecs
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/ijsecs.v3i2.306

Abstract

Social engineering is a psychological manipulation technique used by attackers to exploit human weaknesses in information security. This research aims to identify the challenges organizations face in protecting themselves from social engineering attacks and offer effective solutions. Through analysis of case studies and relevant literature, it was found that a lack of employee awareness and training is one of the main causes of the success of these attacks. In addition, many organizations still rely on inadequate technology to detect threats. To address these issues, this paper recommends implementing regular training programs, strengthening security policies, and using advanced technology. With this comprehensive approach, organizations can strengthen their defences and reduce the risks associated with social engineering. Organizations should prioritize continuous education programs, foster a culture cantered on security, and establish protocols that encourage alertness. Moreover, robust access controls, defined incident reporting processes, and the use of technology like behavioural analytics can further reduce the risks posed by social engineering.
Deep Learning in Wazuh Intrusion Detection System to Identify Advanced Persistent Threat (APT) Attacks Budi Wibowo; Aji Nurrohman; Luqman Hafiz
International Journal of Science Education and Cultural Studies Vol. 4 No. 1 (2025): IJSECS
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/ijsecs.v4i1.311

Abstract

Advanced Persistent Threats (APTs) pose a significant challenge in modern cybersecurity by leveraging persistent and sophisticated methods to compromise organizations. These threats employ advanced techniques such as encrypted communication, polymorphic malware, and log tampering, to evade detection, exfiltrate sensitive data, and disrupt critical infrastructure. Such characteristics often render conventional security measures ineffective in mitigating or preventing such attacks. This study adopted an experimental approach to assess the application of Wazuh, an advanced open-source security platform, in countering APT attacks. By simulating attack scenarios and analyzing real-time logs from diverse sources, Wazuh demonstrated strong intrusion detection capabilities, identifying attack patterns such as brute force attempts and unauthorized directory access. The findings underscore Wazuh’s effectiveness in enhancing organizational resilience by enabling rapid detection and response to suspicious activities. This research highlights how integrated log analysis can address the stealthy nature of APTs. Future studies should explore the integration of machine learning with platforms like Wazuh to further enhance automated and predictive threat detection capabilities, thereby strengthening defenses against evolving strategies of APTs.
Unveiling the Cybercrime Ecosystem: Impact of Ransomware-as-a-Service (RaaS) in Indonesia Budi wibowo; Luqman Hafiz; Taufik Hidayat
International Journal of Science Education and Cultural Studies Vol. 4 No. 1 (2025): IJSECS
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/ijsecs.v4i1.320

Abstract

This study explores the rise of Ransomware-as-a-Service (RaaS) in Indonesia’s cybercrime ecosystem, highlighting its role as a significant digital security threat. RaaS lowers the technical barriers to executing ransomware attacks, enabling individuals with minimal expertise to launch sophisticated cyberattacks. Analyzing data from 2020 to 2024, this study identified Indonesia as a hotspot for RaaS-driven cybercrime in Southeast Asia due to low cybersecurity awareness and weak regulatory frameworks. Key findings reveal that government administration, healthcare, and finance are the most frequently targeted sectors due to their sensitive data and inadequate defense capabilities. Ransomware variants such as Luna Moth and WannaCry, dominate the malware landscape by employing tactics like phishing and exploiting outdated systems. These attacks result in severe socioeconomic consequences, including financial losses, operational disruptions, and reputational damage. This study contributes to our understanding of RaaS by examining its operational, economic, and regulatory dimensions in the Indonesian context. This underscores the urgent need for strengthened cybersecurity policies, public-private sector collaboration, and international cooperation to address transnational cybercrime. By providing actionable insights into attack patterns and mitigation strategies, this study aims to guide efforts to combat ransomware threats and enhance Indonesia’s digital resilience.
Development of an IoT-Based Smart Waste Bin with Automated Operation and Capacity Monitoring Pria Intiadi; Gunawan Sihaloho; Al Fauzan Dito Prasetyo; Budi Wibowo
International Journal of Science Education and Cultural Studies Vol. 4 No. 2 (2025): ijsecs
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/ijsecs.v4i2.379

Abstract

In many public facilities, waste bins are still monitored through routine manual checks, which often results in delayed collection when the bin reaches its capacity. This situation is commonly found in campus park areas, where waste overflow reduces cleanliness and user comfort. This research aims to design and evaluate an IoT-based smart waste bin system that integrates automated lid operation and real-time capacity monitoring to improve waste management efficiency in public spaces. The system uses an ESP32 microcontroller together with an ultrasonic sensor to estimate the waste level and a Passive Infrared (PIR) sensor to detect human presence near the bin. An OLED display is included to show local system status, while remote monitoring and notifications are handled through the Blynk Console platform. The methodology involves system design, algorithm development, and simulation-based testing using the Wokwi platform. During operation, the bin lid opens when motion is detected and closes automatically after a short period. The waste level is observed continuously, and a notification is sent when the predefined capacity threshold is reached. Simulation results demonstrate an average accuracy of 98.8% for capacity detection with an absolute error of 1.2%. The system successfully performed automated lid operations, real-time status display on OLED, RGB LED status indication, and timely notifications via Blynk Console. These findings indicate that the proposed IoT-based smart waste bin can significantly enhance waste management operations in public areas by enabling proactive collection scheduling and reducing overflow incidents, thereby contributing to improved environmental hygiene and operational efficiency.
Cybersecurity Education Strategies Based on Open-Source Intelligence (OSINT) to Enhance Public Awareness Taufik Hidayat; Budi Wibowo; Andrie Yuswanto; Annisa Fathul Jannah
International Journal of Science Education and Cultural Studies Vol. 4 No. 2 (2025): ijsecs
Publisher : Sultan Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58291/ijsecs.v4i2.422

Abstract

In today’s rapidly evolving digital landscape, cybersecurity threats are escalating in both frequency and complexity, which points to the urgent need for effective educational approaches to enhance public awareness. Open-Source Intelligence (OSINT), which leverages publicly available information, offers a practical framework for identifying and understanding cyber risks. This study proposes the design, implementation, and evaluation of an OSINT-based cybersecurity education strategy aimed at non-technical audiences. Employing a mixed-methods approach including literature review, module development, and surveys, this research measures the strategy’s effectiveness in improving cybersecurity comprehension. The results indicate that the OSINT-based educational approach significantly enhances participants’ understanding of cyber risks, yielding an average increase of 35% in comprehension scores. Furthermore, the integration of real-world OSINT demonstrations makes cybersecurity threats more tangible and personally relevant, thereby motivating proactive preventive behavior. In conclusion, incorporating OSINT into cybersecurity education provides an effective and scalable strategy for improving public awareness and resilience against modern digital threats.