Jurnal Ilmiah Multidisiplin Indonesia
Vol. 5 No. 03 (2026): Jurnal Ilmiah Multidisplin Indonesia (JIM-ID), March 2026

Modeling and Simulating Cyber Attacks Using Attack Trees and Security Testing Tools: A Case Study of an ICT Department

D Jayus Nor Salim (Department of Information Technology, Universitas Tidar, Magelang, Indonesia)



Article Info

Publish Date
30 Mar 2026

Abstract

The increasing reliance of higher education institutions on information systems has significantly expanded the cyber attack surface, making academic environments attractive targets for cyber threats. This study proposes an attack tree–based approach to model and simulate potential cyber attacks against an academic information system managed by an ICT department. The research employs a controlled case study design, combining technical attack simulation and analytical modeling to identify realistic attack paths and prioritize mitigation strategies. Cyber attack simulations were conducted in a staging environment using Nmap for network reconnaissance, OWASP ZAP for dynamic web application security testing, and SQLMap for controlled verification of potential SQL injection vulnerabilities. The results of these simulations were systematically mapped into an attack tree model, representing hierarchical attack paths from initial reconnaissance to exploitation and potential impact. Each node in the attack tree was evaluated based on likelihood and impact to support risk prioritization. The findings indicate that the most critical attack paths are associated with web application vulnerabilities and weaknesses in authentication mechanisms, which may lead to unauthorized access and data exposure if left unmitigated. The attack tree model effectively integrates technical evidence from multiple tools into a structured analytical framework, enabling clearer visualization of attack feasibility and mitigation priorities. This study demonstrates that attack tree–based modeling can serve as a practical and systematic approach to strengthening cybersecurity posture in academic ICT departments..

Copyrights © 2026






Journal Info

Abbrev

esaprom

Publisher

Subject

Agriculture, Biological Sciences & Forestry Computer Science & IT Earth & Planetary Sciences Engineering Physics

Description

Jurnal Ilmiah Multidisiplin Indonesia (JIM-ID) is a peer-reviewed journal regularly published by the SEAN Institute every three months. namely, several research publications to publish multi-disciplinary articles with general topics on engineering, science, agriculture, plantations, forestry and ...