Jurnal Ilmiah Universitas Batanghari Jambi
Vol 24, No 3 (2024): Oktober

Perbandingan Evaluasi Kerentanan Menggunakan Tenable Nessus Scanner dan Owasp Zed Attack Proxy untuk Meningkatkan Keamanan Sistem Informasi Kepegawaian di Universitas Merdeka Malang

Wenny, Rizca (Unknown)
Pamuji, Fandi Yulian (Unknown)



Article Info

Publish Date
27 Oct 2024

Abstract

This study aims to compare the vulnerability analysis between Tenable Nessus Scanner and OWASP Zed Attack Proxy (ZAP) for improving the security of the Human Resource Information System (HRIS) website at Universitas Merdeka Malang. The research methodology includes the use of both Nessus and OWASP ZAP tools to scan the HRIS website for potential vulnerabilities. The findings of this research indicate that OWASP ZAP identified several critical web application vulnerabilities such as the absence of Anti-CSRF tokens, lack of Content Security Policy (CSP) headers, and missing Anti-Clickjacking headers, which are essential for maintaining the security and integrity of user data. On the other hand, Nessus Scanner focused more on network and server infrastructure vulnerabilities. The results suggest that OWASP ZAP is more effective for web application security in this context. Recommendations are provided to address the identified vulnerabilities and enhance the overall security of the HRIS website.

Copyrights © 2024






Journal Info

Abbrev

ilmiah

Publisher

Subject

Agriculture, Biological Sciences & Forestry Civil Engineering, Building, Construction & Architecture Economics, Econometrics & Finance Education Law, Crime, Criminology & Criminal Justice

Description

Jurnal Ilmiah Universitas Batanghari Jambi adalah peer-review jurnal akses terbuka yang bertujuan untuk berbagi dan diskusi mengenai isu dan hasil penelitian yang lagi hangat pada saat ini. Jurnal ini diterbitkan oleh Lembaga Penelitian dan Pengabdian pada Masyarakat Universitas Batanghari Jambi, ...