Ferhat Aziz
Universitas Pamulang

Published : 4 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 4 Documents
Search

Advanced Persistent Threats Analysis and Intrusion Detection Systems Evaluation Dedy Wibowo; Taswanda Taryo; Ferhat Aziz
International Journal Software Engineering and Computer Science (IJSECS) Vol. 5 No. 3 (2025): DECEMBER 2025
Publisher : Lembaga Komunitas Informasi Teknologi Aceh (KITA)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35870/ijsecs.v5i3.5770

Abstract

- Advanced Persistent Threats are significant cybersecurity threats that employ covert and strategically planned operations to achieve long-term unauthorized access and data exfiltration. PT XYZ, a logistics company with considerable operational and customer data, is more susceptible to APTs, which is why the company decided to implement Wazuh as an open-source SIEM platform for improved intrusion detection capabilities. We assessed how effectively this IDS-SIEM implementation could detect and respond to APT scenarios by analyzing multi-source logs from Wazuh, Sysmon, and endpoint telemetry across PT XYZ’s PC infrastructure between June 3-30, 2025—capturing 35,333 records in total. Simulated APT attacks were carried out using Atomic Red Team with detection mapping based on MITRE ATT&CK tactics. Most of the early stages of attack phases were identified by Wazuh particularly Initial Access and Execution phases where the system logged 1,060 true positives; 8,537 true negatives; 563 false positives; and 440 false negatives at an accuracy rate of 91%. Normal traffic detection results were good with a precision of 0.95, recall of 0.94 F1-score at the same value whereas attack detection had a precision value of 0.65 with a recall of 0.71 giving it an F1 score of 0.68 making macro-averaged metrics fall at values such as 0.80 for precision and 0.82 for recall which further brought the F1 score up to 0.81 while weighted averages peaked at 0.91.Our results indicate that an open-source SIEM like Wazuh can be used effectively for the detection of APTs in logistics operations when configured appropriately using MITRE ATT&CK-based threat simulations – hence having real-world applicability towards improving cybersecurity defenses within this sector.
SIMULASI MITIGASI ZERO-TOUCH PADA SERANGAN BRUTE FORCE SSH DAN RDP BERBASIS ORKESTRASI SIEM WAZUH Putu Dedi Juliana; Arya Adhyaksa Waskita; Ferhat Aziz
INTECOMS: Journal of Information Technology and Computer Science Vol. 9 No. 2 (2026): INTECOMS: Journal of Information Technology and Computer Science
Publisher : Institut Penelitian Matematika, Komputer, Keperawatan, Pendidikan dan Ekonomi (IPM2KPE)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31539/w7g4ba46

Abstract

Administrasi server berbasis Secure Shell (SSH, port 22) dan Remote Desktop Protocol (RDP, port 3389) pada infrastruktur layanan publik, khususnya Layanan Pengadaan Secara Elektronik (LPSE) Kabupaten Mahakam Ulu, secara inheren memperluas permukaan serangan terhadap Teknik brute force (MITRE ATT&CK T1110). Model mitigasi manual yang bergantung pada analis memperpanjang jarak antara deteksi kegagalan logon berulang dan kontainmen, sehingga membuka jendela eksploitasi yang dapat dimanfaatkan penyerang. Penelitian ini merancang dan memvalidasi prototipe simulasi mitigasi otomatis berbasis semantic Active Response Wazuh dalam kerangka Security Information and Event Management (SIEM). Arsitektur klien–pelayan (React/Vite pada sisi klien; Node.js/Express dengan persistensi JSON pada sisi pelayan) menjalankan tiga skenario pengujian fungsional: serangan brute force bersumber tunggal pada SSH, bersumber tunggal pada RDP, dan multi-sumber dengan tiga alamat IP berotasi. Setiap skenario menggunakan ambang 10 kegagalan autentikasi untuk memicu aturan deteksi 5710 (SSH) dan 60122 (RDP) beranotasi T1110, dilanjutkan eksekusi Active Response berupa firewall-drop (Linux) dan netsh.exe (Windows). Hasil pengujian menunjukkan Mean Time to Respond (MTTR) diskret sebesar satu tick simulasi pada ketiga skenario, dengan rasio keberhasilan isolasi alamat IP mencapai 100% terhadap himpunan sumber yang dimodelkan. Prototipe yang tervalidasi berfungsi sebagai cetak biru konseptual bagi perencanaan penerapan SIEM pada infrastruktur publik tanpa risiko gangguan layanan produksi.
EVALUASI TINGKAT KEAMANAN SERVER LINUX UBUNTU MELALUI PENERAPAN CIS BENCHMARKS, OPENVAS, DAN LYNIS SEBAGAI UPAYA MITIGASI VEKTOR SERANGAN Mohammad Bahtiar; Taswanda Taryo; Ferhat Aziz
INTECOMS: Journal of Information Technology and Computer Science Vol. 9 No. 2 (2026): INTECOMS: Journal of Information Technology and Computer Science
Publisher : Institut Penelitian Matematika, Komputer, Keperawatan, Pendidikan dan Ekonomi (IPM2KPE)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31539/ht1ydz84

Abstract

Server berbasis Linux Ubuntu rentan terhadap berbagai vektor serangan siber akibat konfigurasi bawaan yang berorientasi pada fungsionalitas daripada keamanan. Penelitian ini mengevaluasi tingkat keamanan server Ubuntu Linux 24.04 LTS melalui penerapan CIS Benchmarks v1.0.0, menggunakan OpenVAS untuk pemindaian kerentanan eksternal dan Lynis untuk audit konfigurasi internal, dengan pendekatan eksperimental pre-test/post-test pada lingkungan virtual VMware yang terisolasi. Implementasi mencakup 147 kontrol CIS pada 8 domain keamanan secara iteratif. Hardening Index (HI) Lynis meningkat dari 60 menjadi 83 (+23 poin, +38,3%), melampaui target minimum HI >= 80. Seluruh 3 kerentanan OpenVAS -- ICMP Timestamp Reply Information Disclosure (CVE-1999-0524), TCP Timestamps Information Disclosure, dan Weak MAC Algorithm(s) Supported pada SSH -- berhasil dieliminasi sepenuhnya (100%). Kedua warnings Lynis tereliminasi dan suggestions berkurang dari 32 menjadi 11 (65,6%). Penelitian ini menyediakan bukti empiris pertama untuk kombinasi Ubuntu 24.04 LTS + CIS v1.0.0 + dual-scanner (OpenVAS + Lynis) dalam desain pre/post-test terstruktur, sekaligus panduan hardening berbasis data bagi administrator sistem.
Advanced Persistent Threats Analysis and Intrusion Detection Systems Evaluation Dedy Wibowo; Taswanda Taryo; Ferhat Aziz
International Journal Software Engineering and Computer Science (IJSECS) Vol. 5 No. 3 (2025): DECEMBER 2025
Publisher : Lembaga Komunitas Informasi Teknologi Aceh (KITA), Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35870/ijsecs.v5i3.5770

Abstract

- Advanced Persistent Threats are significant cybersecurity threats that employ covert and strategically planned operations to achieve long-term unauthorized access and data exfiltration. PT XYZ, a logistics company with considerable operational and customer data, is more susceptible to APTs, which is why the company decided to implement Wazuh as an open-source SIEM platform for improved intrusion detection capabilities. We assessed how effectively this IDS-SIEM implementation could detect and respond to APT scenarios by analyzing multi-source logs from Wazuh, Sysmon, and endpoint telemetry across PT XYZ’s PC infrastructure between June 3-30, 2025—capturing 35,333 records in total. Simulated APT attacks were carried out using Atomic Red Team with detection mapping based on MITRE ATT&CK tactics. Most of the early stages of attack phases were identified by Wazuh particularly Initial Access and Execution phases where the system logged 1,060 true positives; 8,537 true negatives; 563 false positives; and 440 false negatives at an accuracy rate of 91%. Normal traffic detection results were good with a precision of 0.95, recall of 0.94 F1-score at the same value whereas attack detection had a precision value of 0.65 with a recall of 0.71 giving it an F1 score of 0.68 making macro-averaged metrics fall at values such as 0.80 for precision and 0.82 for recall which further brought the F1 score up to 0.81 while weighted averages peaked at 0.91.Our results indicate that an open-source SIEM like Wazuh can be used effectively for the detection of APTs in logistics operations when configured appropriately using MITRE ATT&CK-based threat simulations – hence having real-world applicability towards improving cybersecurity defenses within this sector.