Prathama, Muhammad Rayhan Islamiah (2025) ANALISIS RISIKO DAN STRATEGI PERLINDUNGAN SISTEM TERHADAP ANCAMAN SIBER PADA WEBSITE 'SAMBANG' KABUPATEN JOMBANG. Undergraduate thesis, Universitas Muhammadiyah Malang.
PENDAHULUAN.pdf
Download (2MB) | Preview
BAB I.pdf
Download (1MB) | Preview
BAB II.pdf
Download (1MB) | Preview
BAB III.pdf
Download (2MB) | Preview
BAB IV.pdf
Restricted to Registered users only
Download (3MB) | Request a copy
BAB V.pdf
Restricted to Registered users only
Download (919kB) | Request a copy
POSTER.pdf
Restricted to Registered users only
Download (1MB) | Request a copy
Abstract
This research aims to analyze security risks and formulate system
protection strategies against cyber threats on the “SAMBANG” website
owned by the Jombang Regency Government. The research approach used is
exploratory qualitative through observation, literature study, and nondestructive penetration testing based on OWASP and NIST standards. The
results of the study show that the “SAMBANG” website still has a number of
vulnerabilities with a high level of risk, especially in the Open Data,
Statistical Data, Data Catalog, and Data Request features, which are
vulnerable to Cross-Site Scripting (XSS) attacks, both reflected and stored.
In addition, the potential risk of SQL Injection was identified, although it was
not directly exploited, as well as authentication weaknesses on the login page
that were vulnerable to brute force. The Data Request form was also found to
lack a Cross-Site Request Forgery (CSRF) token mechanism, making it
potentially exploitable by attackers. This study recommends the
implementation of input validation, output encoding, Content Security Policy
(CSP), prepared statements, multi-factor authentication, login restrictions,
and file upload validation to improve system protection. With these results,
the study provides practical contributions for regional public information
system managers in strengthening government website security and building
more adaptive cyber resilience.
| Item Type: | Thesis (Undergraduate) |
|---|---|
| Student ID: | 202010370311333 |
| Keywords: | Cybersecurity, Risk Analysis, Government Websites, SQL Injection, XSS |
| Subjects: | T Technology > TA Engineering (General). Civil engineering (General) T Technology > TK Electrical engineering. Electronics Nuclear engineering Z Bibliography. Library Science. Information Resources > ZA Information resources Z Bibliography. Library Science. Information Resources > ZA Information resources > ZA4050 Electronic information resources |
| Divisions: | Faculty of Engineering > Department of Informatics (55201) |
| Depositing User: | 202010370311333 mrrayhankagami |
| Date Deposited: | 17 Nov 2025 06:33 |
| Last Modified: | 17 Nov 2025 08:24 |
| URI: | https://eprints.umm.ac.id/id/eprint/25080 |
