INTENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi
Vol 7 No 1 (2023): February 2023

Security Analysis of Simpel Desa using Mobile Security Framework and ISO 27002:2013

Khairunnisak Nur Isnaini (Universitas Amikom Purwokerto)
Didit Suhartono (Universitas Amikom Purwokerto)



Article Info

Publish Date
10 Feb 2023

Abstract

The Personal Identification Number or KTP is prone to be stolen and used by unwanted parties, this is also a possibility for the Simpel Desa, a village administration application that also contain and use the Personal Identification Number. This study aims to detect information security vulnerabilities. This study aims to analyze security vulnerabilities in applications using MobSF and ISO 27002:2013. MobSF is used for penetration testing for malware in applications. In MobSF the Simpel Desa application is analyzed in two ways, namely static and dynamic. ISO 27002:2013 is used to map the findings of vulnerabilities and potential misuse of information so that they get accurate analysis results. The control used is domain 9 (access control) and 10 (cryptography). The results obtained in the static analysis found the existence of vulnerabilities in aspects of cryptography and permission access. The dynamic analysis found that Root Detection and Debugger Check Bypass had not been implemented. Overall, based on ISO 27002:2013 information security has not been maximally implemented. The recommendations given focus on the aspects of application permissions and access rights, user authentication, and the implementation of information security.

Copyrights © 2023






Journal Info

Abbrev

intensif

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management

Description

INTENSIF Journal is a publication container for research in various fields related to information systems. These fields includeInformation System, Software Engineering, Data Mining, Data Warehouse, Computer Networking, Artificial Intelligence, e-Bussiness, e-Government, Big Data, Application ...