Indonesian Journal of Electrical Engineering and Renewable Energy (IJEERE)
Vol 6 No 1 (2026): IJEERE Juni 2026

Trusted Hardware, Untrusted Operators: An Insider-Enabled Threat Taxonomy for National Computer-Based Testing Infrastructure: Perangkat Keras Terpercaya, Operator Tak Terpercaya: Taksonomi Ancaman Berbasis Orang-Dalam untuk Infrastruktur Ujian Nasional Berbasis Komputer

Mulkan Fadhli (UIN Arraniry Aceh)



Article Info

Publish Date
29 Jun 2026

Abstract

The security literature on computer-based testing (CBT) has developed almost entirely around remote proctoring, where the threat model assumes untrusted examinee-owned hardware operating in an uncontrolled environment. This framing treats institution-controlled hardware under physical invigilation as a secure baseline. We argue this assumption is unsound, substantiating the argument with evidence from Indonesia's national university entrance examination (UTBK-SNBT), a high-stakes CBT administered to 871,496 registered candidates in 2026 (846,518 present) across a distributed network of state-university testing centres. Drawing on publicly documented incidents from the 2025 and 2026 administrations, we reconstruct two organised attacks in which institution-controlled examination hardware was compromised despite physical proctors, metal detectors, and closed-circuit surveillance. In the first, campus IT staff with legitimate administrative privileges installed remote-access software on examination workstations; nine suspects were charged under Articles 30 and 32 of the Electronic Information and Transactions Law. In the second, a covert proxy appliance comprising two mini PCs, a router, and an uninterruptible power supply was concealed within a printer carton approximately six months before the examination. From these incidents we derive a five-class threat taxonomy and construct a STRIDE-based threat model mapped to MITRE ATT&CK. We show that the only control demonstrably effective against the most sophisticated attack was network-layer anomaly detection, whereas the perimeter controls emphasised in policy discourse failed by design. We conclude that trusted-hardware CBT constitutes a distinct, under-theorised threat model, and we outline a research agenda for its systematic study.

Copyrights © 2026






Journal Info

Abbrev

ijeere

Publisher

Subject

Computer Science & IT Control & Systems Engineering Electrical & Electronics Engineering Energy Engineering Environmental Science

Description

Indonesian Journal of Electrical Engineering and Renewable Energy (IJEERE) is a scientific journal published by the Institute Research and Publication Indonesia (IRPI) in collaboration with several universities throughout Riau and Indonesia. IJEERE will be published 2 (two) times a year, June and ...