Ransomware is a type of malware that encrypts the victim's data and demands a ransom to restore access, with WannaCry being one of the most notorious variants exploiting EternalBlue on the SMB protocol. This study compares static and dynamic analysis methods in detecting WannaCry ransomware to evaluate their effectiveness. Static analysis is performed without executing the ransomware, using too…
As the most widely used mobile operating system, Android is increasingly becoming a prime target for malware attacks. The popularity of this operating system makes it attractive for cyber security criminals to steal valuable data, one of which is by installing Android malware applications. Several studies have used various Machine Learning (ML) methods to recognize Android malware applications …
Malware that can enter through PDF files that appear unsuspicious is one of the main factors in cyber security attacks. The GARUDA dataset was analyzed statically using VirusTotal and PDFiD to identify whether a PDF file is dangerous or not, then classification was carried out to determine the characteristics of the PDF file using the Logistic Regression method of the Multinomial type. The data…
Spyware is one type of malware that threatens computer systems because it can steal users' personal information and sensitive data without their knowledge. Spyware can monitor user activities and steal data such as visited websites, email addresses, and even record keyboard and screen activities. This research aims to classify spyware attacks using the K-Nearest Neighbors (KNN) algorithm. The r…
K-means clustering is a tool for determining the cluster structure of a data set identified by its strong similarity to other clusters or its strong differences from other clusters. Another article says that the working method of the K-Means algorithm requires using centroids as cluster prototypes and previous cluster results as output. The dataset comes from CIC-MalMem2022 provided by UNB CIC.…
Malware is malicious software that refers to programs that deliberately exploit vulnerabilities in computing systems for malicious purposes, Deep Neural Network is an Artificial Neural Network with several layers between the input and output layers, Deep Neural Network has become an alternative to Machine Learning because of advances significant in the Deep Neural Network training algorithm can…
Spyware is a type of malware that aims to collect important information and data such as financial information and passwords without permission and send them to the attacker. Visualization techniques are needed to make it easier to analyze attack patterns and characteristics of spyware. This study used the Random Forest algorithm. The dataset is from CIC-MalMem2022 with benign data types and Sp…
Android is the most popular mobile software platform across the globe. The worldwide app downloads reached 352.9 billion in 2021. However, it still faces serious security threats due to its open-source nature. Android is susceptible to various malware variants that are packaged within APK (Android Package Kit) files and have permissions for SMS (Short Message Service). SMS is a technology used …
This research focuses on the utilization of Deep Learning techniques for malware detection and classification. By representing malware samples as grayscale images, a Deep Learning model based on Convolutional Neural Networks (CNN) is developed. The model is trained using a dataset containing grayscale malware samples. Experimental results demonstrate a high level of accuracy of the Deep Learnin…
Garba Rujukan Digital (GARUDA) merupakan salah satu e-library akademisi Indonesia yang memakai PDF sebagai ekstensi file. Dataset yang digunakan dalam penelitian ini berasal dari portal GARUDA dengan data sebanyak 10000 yang terdiri dari 9800 benign, 196 malicious html, dan enam malicious pdf. Dataset dianalisis menggunakan VirusTotal, PDF-parser dan PDFid. Proses klasifikasi dilakukan sebanyak…
K-Means clustering is a method to grouping data based on the similarity of features and detect the hidden patterns in dataset. The dataset is from GARUDA Repository which contains raw data of PDF files. GARUDA dataset extraction process used static analysis method. The data extraction process produced twenty�one features using PDFiD. GARUDA dataset has a multi-class and imbalanced data, there…
The amount of Malware is constantly increasing. Most Malware is a modification of previous Malware data. The datasets used from CIC-MalMem-2022 are Benign and Spyware-CWS. This study used the Naïve Bayes Classifier algorithm. Naïve Bayes is one of the classification algorithms that has accuracy in making predictions and has a good reputation in classification, especially in learning speed com…
In the security sector, malware that specifically attacks smartphones is growing faster and more sophisticated. Malware is becoming more and more powerful in carrying out criminal acts, such as stealing and destroying important data and information stored on mobile phones, thus demanding the creation of an anti-malware system that can prevent and detect when carrying out malware attacks on smar…
Portable Document Format (PDF) is a document exchange media that is very vulnerable to malicious attacks, namely Malware PDF. One of the services that most often use PDF files as a medium is a scientific publication service Garba Rujukan Digital (GARUDA). Therefore, research was conducted using static analysis methods for each PDF and data extraction using PDFiD. Based on these research, it fou…
The Portable Document Format (PDF) is one of the most commonly used document reader formats, the object structure in PDF is flexible and easy to use. Therefore, that hackers use PDFs to carry out the attacks. The dataset comes from the Garba Rujukan Digital (GARUDA), which consists of a collection of PDF files. PDF files will extract using the pdfid tools to get features used in the multiclass …
Virus, trojan, dan semua komplotannya meupakan program jahat yang selalu mempunyai tujuan untuk menghancurkan, merusak data serta sistem komputer dan Android yang kita miliki. Virus tidak pernah pilih kasih, tidak pandang bulu, dan tidak mempunyai bebas kasihan sedikit pun. Untuk itu, jangan sampai semua itu terjadi dan menimpa pada diri Anda. Bentengi segera komputer, laptop, Android, dan s…
The internet is a liaison between one electronic media and other electronic media quickly and accurately in acommunication network. Where the communication network sends information that is transmitted by signaling at an adjusted frequency[3]. Adware is software that is used to display advertisements for monetary gain[6]. The dataset comes from the Canadian Institute for Cybersecurity (CIC) wit…
Visualization is a method used to represent data in the form of an image to display hidden information. The visualization in this study uses malware data to be converted into a grayscale image. This study uses 10 types of malware with a total of 1000 data. The test data is divided into training data as much as 80% of the test data is 20% of the total data. Malware is tested using Local Binary P…
The development of technology triggers the development of malicious files called malware. Malware is software that is explicitly designed with the aim of finding weaknesses or even damaging software or operating systems. In this study, the dowgin and benign malware classification was carried out using the Random Forest algorithm method by comparing weka data and spyder programs. The dataset use…
Slow http dos attack is one of the DoS attack methods targeting HTTP servers. This method hampers the service by flooding it causing a pool of connections with slow and heavy requests to the web server. It is known that a slow HTTP DoS attack by a single attacker can be effectively prevented by limiting the number of connections for each IP address. The purpose of this study is to obtain the be…
Malware adalah sebuah perangkat lunak yang dibuat dengan tujuan memasuki dan terkadang merusak sistem komputer, jaringan, ataupun server tanpa diketahui oleh pemiliknya, Ransomware merupakan jenis malware tertentu yang akan menuntut tebusan finansial dari korban dengan cara mengancam akan mempublikasikan, menghapus, atau juga menahan akses ke data pribadi yang penting. Pada penelitian ini akan …
Serangan SQL Injection dan XSS adalah salah satu contoh serangan kerentanan yang ada di aplikasi web. Serangan SQL Injection adalah salah satu dari lima teratas dalam semua risiko keamanan aplikasi web. Serangan SQL Injection dilakukan dengan memasukkan perintah sql ke dalam bentuk web, nama domain, atau permintaan halaman, dan akhirnya menipu server untuk menjalankan perintah SQL yang berbahay…
Distributed Denial of Service (DDoS) merupakan serangan yang dapat mengganggu lalu lintas sebuah jaringan dengan memanfaatkan mesin zombie yang dikendalikan oleh penyerang. Serangan HTTP Flood dilakukan dengan mengeksploitasi permintaan HTTP GET dan HTTP POST ke target yang diserang. Pada penelitian ini menggunakan dataset CSE-CIC-IDS 2018 yang berasal dari University Of New Brunswick (UNB). Di…
Reduksi dimensi sudah banyak dipakai berbagai penelitian didunia karena fungsinya yang baik dalam memperkecil data tanpa menghilangkan karakteristik dari data trsebut. Pada penelitian ini ingin melihat bagaimana peningkatan hasil yang akan didapatkan untuk melakukan klasifikasi jika menggunakan reduksi dimensi pada data yang ingin digunakan. Pada penelitian kali ini menggunakan reduksi dimensi …
RAMA repository merupakan tempat penyimpanan paparan hasil penelitian nasional baik berbentuk tugas akhir proyek mahasiswa (Diploma), skripsi (S1), tesis (S2), disertasi (S3) maupun laporan penelitian lainnya. Hal ini membuat RAMA repository rentan terhadap serangan database online diantaranya injeksi SQL dan XSS. Serangan injeksi SQL merupakan serangan database online diurutan pertama, dimana …
Denial of Service (DoS) adalah teknik serangan yang sering dilakukan oleh attacker yang bertujuan untuk melumpuhkan kemampuan sistem. Serangan dari Denial of Service (DoS) merupakan ancaman yang serius dalam jaringan saat ini, Serangan Smurf merupakan serangan yang dapat memanfaatkan IP dari Host target sebagai sumber ICMP Request, serta mendapat keuntungan terhadap protokol jaringan paket ICMP…
Pada beberapa tahun terakhir penelitian mengenai botnet telah banyak dilakukan, botnet merupakan salah satu jenis malware yang menyerang dengan cara mengambil alih sistem komputer yang terhubung ke jaringan internet dengan mengendalikannya secara remote. Penelitian ini menggunakan dataset MedBIoT yang berasal dari Tallinn University of Technology terdapat tiga jenis botnet yaitu bashlite, mirai…
Android smartphones is widely used for banking transactions. Thus, it can be at risk of malware attacks. Malware classification is a method that serves to identify and distinguish types of data classified as malware or normal. Banking Malware is malware designed to gain access to user's online banking accounts by impersonating a real banking application or web banking interface. This study aims…