Publication Search

79,575 articles from 739 journals · 2,111 citations tracked

Showing 1-9 of 9

Analytics

Dian Suryo Aji; Dwi Safiroh Utsalina

JURNAL PENELITIAN SISTEM INFORMASI 2026 Institut Teknologi dan Bisnis (ITB) Semarang

The increasing use of web applications in various sectors has made security a major concern due to the high risk of attacks targeting the application layer. This study aims to analyze the effectiveness of the F5 Web Application Firewall (F5 WAF) in mitigating vulnerabilities in the OWASP Juice Shop application. Testing was conducted using 10 attack scenarios including SQL Injection, Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), and Information Disclosure before and after F5 WAF implementation. The test results showed that all tested attack scenarios were successfully mitigated after F5 WAF implementation. These findings indicate that the F5 WAF is able to provide effective protection against various vulnerabilities at the application layer and improve the security of web applications in the test environment used.

Parhusip, Jose Elio; Ginasta, Nava Gia; Hanum, Rahma; Parhusip, Jose Elio; Ginasta, Nava Gia +1 more

JUISI : Jurnal Ilmiah Sistem Informasi 2026 LPPM Universitas Sains dan Teknologi Komputer

Penelitian ini bertujuan: (1) mengembangkan sistem input nilai kinerja karyawan agar lebih akurat dan efisien; (2) merancang Entity Relationship Diagram (ERD) dan struktur basis data untuk mendukung pengolahan data karyawan; serta (3) membangun backend sistem dengan autentikasi dan otorisasi berbasis peran. Ruang lingkup mencakup pengelolaan data kinerja individu yang sebelumnya dilakukan secara manual menggunakan spreadsheet dan rentan terhadap kesalahan input. Metode yang digunakan meliputi pengumpulan data kinerja kuartal kedua, perancangan ERD, serta pengembangan backend web application IHSAN POS menggunakan JavaScript dan framework Express yang terintegrasi dengan PostgreSQL, DBeaver, dan Prisma ORM. Implementasi keamanan dilakukan melalui middleware validasi input, sanitasi data, perlindungan dari serangan SQL injection dan XSS, serta pengelolaan sesi menggunakan enkripsi JWT (JSON Web Token). Sistem yang dikembangkan mencakup enam fitur terintegrasi: Halaman Login, Halaman Profil, Formulir Edit Profil, Halaman Nilai Kinerja Individu dan Kontrak Kerja, Formulir Kontrak Kerja, serta Pratinjau Surat Kontrak Kerja. Hasil pengembangan menunjukkan bahwa sistem backend yang dibangun mampu meningkatkan efisiensi proses evaluasi kinerja, memperbaiki integrasi data, serta mempermudah validasi dan pelaporan secara digital dan terstruktur. Kesimpulannya, pengembangan sistem ini memberikan kontribusi signifikan dalam peningkatan efisiensi, akurasi, dan transparansi evaluasi kinerja karyawan, serta mendukung pengambilan keputusan strategis terkait insentif dan pengembangan karier pegawai.

Oktavia, Divala Zahra; Hidayat , Dwi Alvin; Natalia , Desy; Prabantara, Satria Krisna; Arfriandi, Arief +5 more

JUISI : Jurnal Ilmiah Sistem Informasi 2026 LPPM Universitas Sains dan Teknologi Komputer

Pemanfaatan aplikasi berbasis web yang semakin meluas di berbagai sektor menyebabkan meningkatnya risiko terhadap ancaman siber, termasuk serangan phising, DDoS, injeksi SQL, XSS, serta intrusi. Berbagai metode deteksi tradisional yang bersifat statis sering kali tidak mampu mengidentifikasi pola serangan baru yang bersifat dinamis. Untuk mengatasi keterbatasan tersebut, machine learning muncul sebagai pendekatan yang lebih adaptif karena mampu mempelajari pola perilaku, mendeteksi anomali, dan melakukan deteksi ancaman secara otomatis. Penelitian ini melakukan tijauan sistematis literatur (Systematic Literature Review/SLR) untuk meneliti penggunaan machine learning dalam mengingkatkan keamanan aplikasi web dan mengevaluasi performa beberapa algoritma yang digunakan. SLR dilaksanakan dengan menggunakan kerangka PICOC, yang mencakup populasi, intervensi, perbandingan, hasil, konteks. Hasil analisis menunjukkan bahwa machine learning digunakan untuk berbagai aspek keamanan web, seperti deteksi phising, penentuan URL berbahaya, pengurangan dampak serangan DDoS, serta identifikasi intrusi jaringan. Algoritma seperti Random Forest, XGBoost, dan SVM terbukti memiliki kinerja yang stabil dengan tingkat akurasi yang tinggi. Selain itu, teknik pendukung seperti ADASYN, feature selection, dan metode berbasis pemrosesan bahasa alami turut meningkatkan efektivitas model. Secara keseluruhan, hasil penelitian ini menegaskan bahwa machine learning dapat mempercepat dan meningkatkan ketepatan deteksi ancaman serta memberikan adaptasi terhadap pola serangan yang terus berubah, sehingga menjadi komponen penting dalam memperkuat keamanan aplikasi web.

Kishori, Kishori; Dwi Satria, Muhammad Najib

Dinamik 2026 Universitas Stikubank

Website security is an important aspect of designing a website and managing web systems. However, many developers still pay little attention to security aspects from the early stages of development. In fact, the website that has been built will be the target of attacks by hackers at any time. Therefore, this research aims to analyze the vulnerability of the SMAN 1 Banjar Agung website based on the OWASP Top 10 standard. The research method was conducted through vulnerability assessment using OWASP ZAP tools with the stages of spidering, passive scanning, and active scanning. This test allows identification of vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), and security configuration weaknesses. The scan results showed eight vulnerabilities, consisting of two medium, three low, and three informational vulnerabilities. Although the risk level is low, the website still requires mitigation through the application of security headers, dependency updates, and removal of sensitive information to make the system more secure and stable.

Rahmeisi, Nazli; Gani, Eksa Umar; Arfriandi, Arief; Rahmeisi, Nazli; Gani, Eksa +1 more

JUISI : Jurnal Ilmiah Sistem Informasi 2025 LPPM Universitas Sains dan Teknologi Komputer

The rapid growth of web technologies and online services has increased the exposure of web applications to cyber threats such as Cross-Site Scripting (XSS) and SQL Injection (SQLi). Conventional rule-based mechanisms, such as Web Application Firewalls (WAFs), often fail to detect emerging attack patterns. To address this, Machine Learning (ML) and Deep Learning (DL) have emerged as adaptive approaches for enhancing web attack detection. This study performs a Systematic Literature Review (SLR) following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) 2020 guidelines to analyze recent ML/DL-based detection methods. Of the 263 retrieved studies, 15 met the inclusion criteria for detailed review. The findings reveal that Random Forest (RF), Support Vector Machine (SVM), Convolutional Neural Network (CNN), and Long Short-Term Memory (LSTM) are the most applied algorithms. At the same time, recent works emphasize Transformer-based and hybrid ML–DL models. These approaches achieved robust performance (accuracy 85–97%, F1-score >90%) but still face challenges in dataset representativeness, class imbalance, and computational cost. This review highlights future research directions in Explainable Artificial Intelligence (XAI), Federated Learning (FL), and adversarial robustness to develop more efficient and trustworthy web attack detection systems.

Shalsabila Titanie Harianto; Zahrah Aliyah Rachman; Aliyyah Nabiilah Farahdita; Fahryan Putra Ramadi; Agung Brastama +1 more

Neptunus: Jurnal Ilmu Komputer Dan Teknologi Informasi 2025 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

The development of e-learning platforms has transformed the landscape of education by providing flexible and accessible learning methods. However, security threats targeting web-based applications pose significant risks to the confidentiality, integrity, and availability of academic data. This research aims to analyze the security vulnerabilities of the ILMU2 e-learning website at UPN “Veteran” Jawa Timur using the Web Application Security Project Zed Attack Proxy (OWASP ZAP) methodology. The study applies a black-box testing approach to simulate attacks and identify potential weaknesses in the website's security mechanisms. Expected findings include the identification of vulnerabilities such as cross-site scripting (XSS), SQL injection, and security misconfigurations. The results are intended to provide insights for improving the security posture of the ILMU2 platform and contribute to the broader discourse on securing educational technology in higher education institutions.

Mochammad Fadilah; Nur Nawaningtyas

Merkurius : Jurnal Riset Sistem Informasi dan Teknik Informatika 2024 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

This study aims to analyze security vulnerabilities and mitigation on the crowdo.co.id website using the OWASP Zed Attack Proxy (ZAP) tool, which is a web application security testing tool. High-level security attacks have increasingly risen alongside the advancement of information technology, making vulnerability testing crucial to ensure the integrity and security of information systems. This research involved scanning the crowdo.co.id website to identify various vulnerabilities, including those listed in the OWASP Top 10. The research process encompassed active and passive scanning, data analysis from the scans, and the formulation of mitigation strategies for each identified vulnerability. The findings revealed that the website had 14 detected vulnerabilities, consisting of 1 high-priority vulnerability, 3 medium-priority vulnerabilities, 7 low-priority vulnerabilities, and 3 additional informational alerts. The security dimensions tested included potential XSS attacks, SQL Injection, and other deficiencies that could jeopardize user data. Based on these results, recommended mitigations include code improvements, enhanced security configurations, and the implementation of additional preventive measures. This study concludes that while the website’s security is in the medium category, further improvements are necessary to reduce vulnerability risks. Through this approach, the study provides significant contributions to enhancing web application security.

Angga Putrawansyah PB; Tata Sutabri

Router : Jurnal Teknik Informatika dan Terapan 2024 Asosiasi Profesi Telekomunikasi dan Informatika Indonesia

Security of electronic medical records (EMR) data is very important in maintaining the confidentiality, integrity, and availability of sensitive patient information. This study aims to conduct a security analysis of the EMR application used at UPTD RSD Besemah Pagar Alam City using the Penetration Testing method. This method is carried out to identify, exploit, and provide solutions to potential vulnerabilities in the EMR application system. Penetration Testing is carried out through several stages, namely information collection, scanning, exploitation, and post-exploitation, using tools such as Nmap, and OWASP ZAP. The results of the study showed several vulnerabilities in the application, including SQL Injection, Cross-Site Scripting (XSS), and weaknesses in authentication management that could allow unauthorized access to patient data. In addition, exposure to sensitive data that was not properly protected was also found. Based on the results of this test, several recommendations were made to improve system security, such as updating security patches, implementing encryption on all sensitive data. By implementing the recommended mitigation steps, the security of the EMR system at UPTD RSD Besemah is expected to be significantly improved, so that the risk of data leakage can be minimized. This research provides a real contribution in strengthening the security of electronic medical record applications. and is expected to be a reference in improving security systems in other health care institutions.    

Deski Ari Sandi; Agus Tedyyana

Repeater : Publikasi Teknik Informatika dan Jaringan 2024 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

In the era of information technology advancement, web applications have become a means of seeking information. However, with technological progress, they have become increasingly vulnerable to cyber attacks such as SQL Injection and Cross-Site Scripting (XSS). This research aims to implement the Teler-waf Web Application Firewall (WAF) to protect web applications from such attacks. The research methodology includes the implementation of the Teler-waf WAF, analysis of web application security, and testing the speed of attack detection. The results show that Teler-waf is effective in preventing attacks, and its integration with Telegram bots provides real-time notifications to system administrators, enhancing security responsiveness. This research contributes to strengthening web application security and understanding the role of the Teler-waf WAF in addressing cyber threats.