Claim Missing Document
Check
Articles

Found 3 Documents
Search

Analisis Pola Dan Dampak Serangan Cryptojacking Dengan Menggunakan Pendekatan Dynamic Analysis Nur Widiyasono; Aldy Putra Aldya; Rifan Renanda Ardhian
CESS (Journal of Computer Engineering, System and Science) Vol 6, No 1 (2021): Januari 2021
Publisher : Universitas Negeri Medan

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (1119.092 KB) | DOI: 10.24114/cess.v6i1.20008

Abstract

“Miners” bekerja untuk memecahkan masalah matematika yang kompleks untuk menghasilkan pendapatan dalam bentuk mata uang digital, seperti Bitcoin, Ethereum, Monero, dan lainnya. Proses mining ini membutuhkan perangkat keras yang serius dan sumber daya CPU yang signifikan untuk menciptakan cryptocurrency. Cryptojacking salah satu alat penambangan mata uang digital secara illegal. Cryptojacking dapat memberikan return yang lebih substansial bagi penyerang.Cryptominer jenis ini tidak terlalu membahayakan secara langsung kepada para korbannya, tetapi hanya saja menggunakan akses illegal ke komputer korban dan menggunakan sumber daya korban untuk menambang crypto. Metode yang digunakan adalah dynamic analysis. Dinamic Analysis adalah mencari informasi atau sampel mengenai malware dengan cara menjalankannya. Dengan metode ini dapat terlihat “perilaku” dari malware tersebut sehingga selanjutnya dapat dianalisa dampak yang terjadi. Pengujian malware ini dilakukan dengan 2 cara yaitu pengujian pertama dilakukan dengan javascript injection pada jaringan lokal yang sama dengan korban yaitu wifi publik dan pengujian kedua dengan mengakses website yang terindikasi skrip cryptojacking. Berdasarkan hasil analisis menggunakan dynamic analysis dimana cryptojacking dapat menginfeksi langsung ke website atau melalui jaringan local dengan javascript injection, jika website telah terinfeksi cryptojacking maka pengunjung dari website tersebut akan menjadi korban dan terjadi penambangan tersembunyi yang akan memakan sumber daya korban dan cryptojacking operator dalang dibalik website yang terinfeksi akan menerima keuntungan dalam bentuk mata uang digital dari hasil cryptojacking ini
Stateless Authentication with JSON Web Tokens using RSA-512 Algorithm Alam Rahmatullo; Aldy Putra Aldya; Muhammad Nur Arifin
JURNAL INFOTEL Vol 11 No 2 (2019): May 2019
Publisher : LPPM INSTITUT TEKNOLOGI TELKOM PURWOKERTO

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.20895/infotel.v11i2.427

Abstract

Today's technology needs are getting higher, one of the technologies that continues to grow now is Web Service (WS). WS can increase service flexibility on a system. However, security at WS is one of the things that needs attention. One effort to overcome this problem is JWT (JSON Web Token). JWT is one of the authentication mechanisms in WS, with a standard signature algorithm, HMAC SHA256, RSA-256 or ECDSA. In this research we will discuss the performance of JWT RSA-512 which is implemented on SOAP and RESTful. Because based on previous research the speed performance of the 512-bit algorithm is better, but it is not yet known if applied to JWT. The test results show that the speed of the JWT RSA-512 token on the RESTful process is superior to 24.69% compared to SOAP. Then the speed of the authentication of JWT RSA-512 tokens, RESTful is superior to 11.64% compared to SOAP. Whereas in testing the size of JWT RSA-512 generated tokens, RESTful is only 1.25% superior to SOAP.
Data Integrity Testing of Digital Evidence Data Capture Results on Private Cloud Computing Services Arif Maulana Komarudin; Nur Widiyasono; Aldy Putra Aldya; Randi Rizal
Innovation in Research of Informatics (INNOVATICS) Vol 5, No 2 (2023): September 2023
Publisher : Informatika Universitas Siliwangi

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.37058/innovatics.v5i2.8420

Abstract

Private Cloud has better advantages than other cloud services because private cloud is managed and run by the company itself so that cloud needs can be tailored to the company's needs, but allows abuse from within the company itself, as in the case study simulation of a Gojek startup company. This case occurred because of a security weakness in the system so that internal people took advantage of these weaknesses for their own benefit by leaking confidential data, acquisitions were carried out to prove and find evidence of crime, acquisitions used live acquisition techniques, namely acquisitions on an ongoing system, namely monitoring network traffic using Wireshark tools , the method in this case uses the Digital Forensics Investigating Framework (DFIF), data integrity must be properly maintained when acquiring digital evidence because to maintain the authenticity of the digital evidence obtained, then data integrity is tested on the digital evidence obtained, testing is carried out on digital evidence before and after the acquisition to see if there is a change in data integrity, the research results show that there is no change in data integrity.