The growth of the Android ecosystem in Indonesia has increased the complexity of cybersecurity threats, particularly through the spread of malicious APK files disguised as legitimate applications. Attack methods such as fake digital invitations containing banking malware, as well as the use of obfuscation, polymorphism, and dynamic behavior manipulation techniques, have rendered signature-based…
This study aims to detect and classify Distributed Denial of Service (DDoS) and Man-in-the-Middle (MiTM) attacks in smart home networks using the Light Gradient Boosting Machine (LightGBM) algorithm. With the rapid growth of Internet of Things (IoT) devices, cybersecurity challenges have become crucial due to vulnerabilities in smart home devices. This research utilizes the COMNETS SMARTHOME da…
Smartphones used by everyone are connected to the internet at all times. A user is unaware of how much data they store and display while using various applications. With the increasing number of Android users over time, Android has become a target for cybercriminals, leading to an increase in malware attacks on these devices. Reverse engineering is the most crucial approach in analyzing malware…
The increasing use of Android devices has also led to the rise of security threats, one of which is the Reverse TCP attack technique that enables unauthorized remote access to victim devices. This study aims to develop a malware detection system using the Artificial Neural Network (ANN) method, implemented on a Small Board Computer (SBC), specifically the Banana Pi BPI-R1. Data was collected th…
Android malware threats using reverse TCP techniques are increasing and require effective detection methods. This study develops a detection systemusing the Naïve Bayes algorithm implemented on a small board computer (Banana Pi). Network traffic datasets were created under three scenarios: normal, attack (reverse TCP), and combined. After labeling and preprocessing, the Naïve Bayes model was …
This study aims to detect and classify Distributed Denial of Service (DDoS), Denial of Service (DoS), and Man in The Middle (MITM) attacks on smart home devices using the Naïve Bayes method. The research begins by identifying important features of network traffic such as frame.time.epoch, ip.src, ip.dst, eth.src, eth.dst, tcp.srcport, tcp.dstport, arp, and frame.len, which play a crucial role …
The rapid advancement of Android technology makes this operating system vulnerable to malware attacks, one of which is the Reverse TCP Trojan, capable of establishing a back connection from the victim’s device to the attacker without being detected. This study aims to analyze the characteristics of Android Reverse TCP malware attacks on network traffic and develop a detection model using the …
The rapid development of the open-source Android operating system has made it vulnerable to various cyberattacks, including malware that utilizes the reverse TCP technique. This attack allows an attacker to remotely control a victim’s device through a connection initiated by the device itself, making it difficult to detect using conventional security mechanisms. This research aims to detect r…
Trojan horse is a cyber attack that is carried out by disguising or infiltrating a system through programs or files that appear normal and harmless. Trojan horses can gain unauthorized access into computer systems allowing hackers to carry out various types of attacks and steal users' personal information by taking control of the system remotely. In addition, advances in cyber attack technology…
Ransomware is a type of malware that encrypts the victim's data and demands a ransom to restore access, with WannaCry being one of the most notorious variants exploiting EternalBlue on the SMB protocol. This study compares static and dynamic analysis methods in detecting WannaCry ransomware to evaluate their effectiveness. Static analysis is performed without executing the ransomware, using too…
As the most widely used mobile operating system, Android is increasingly becoming a prime target for malware attacks. The popularity of this operating system makes it attractive for cyber security criminals to steal valuable data, one of which is by installing Android malware applications. Several studies have used various Machine Learning (ML) methods to recognize Android malware applications …
Malware that can enter through PDF files that appear unsuspicious is one of the main factors in cyber security attacks. The GARUDA dataset was analyzed statically using VirusTotal and PDFiD to identify whether a PDF file is dangerous or not, then classification was carried out to determine the characteristics of the PDF file using the Logistic Regression method of the Multinomial type. The data…
Spyware is one type of malware that threatens computer systems because it can steal users' personal information and sensitive data without their knowledge. Spyware can monitor user activities and steal data such as visited websites, email addresses, and even record keyboard and screen activities. This research aims to classify spyware attacks using the K-Nearest Neighbors (KNN) algorithm. The r…
K-means clustering is a tool for determining the cluster structure of a data set identified by its strong similarity to other clusters or its strong differences from other clusters. Another article says that the working method of the K-Means algorithm requires using centroids as cluster prototypes and previous cluster results as output. The dataset comes from CIC-MalMem2022 provided by UNB CIC.…
Malware is malicious software that refers to programs that deliberately exploit vulnerabilities in computing systems for malicious purposes, Deep Neural Network is an Artificial Neural Network with several layers between the input and output layers, Deep Neural Network has become an alternative to Machine Learning because of advances significant in the Deep Neural Network training algorithm can…
Spyware is a type of malware that aims to collect important information and data such as financial information and passwords without permission and send them to the attacker. Visualization techniques are needed to make it easier to analyze attack patterns and characteristics of spyware. This study used the Random Forest algorithm. The dataset is from CIC-MalMem2022 with benign data types and Sp…
Android is the most popular mobile software platform across the globe. The worldwide app downloads reached 352.9 billion in 2021. However, it still faces serious security threats due to its open-source nature. Android is susceptible to various malware variants that are packaged within APK (Android Package Kit) files and have permissions for SMS (Short Message Service). SMS is a technology used …
This research focuses on the utilization of Deep Learning techniques for malware detection and classification. By representing malware samples as grayscale images, a Deep Learning model based on Convolutional Neural Networks (CNN) is developed. The model is trained using a dataset containing grayscale malware samples. Experimental results demonstrate a high level of accuracy of the Deep Learnin…
Garba Rujukan Digital (GARUDA) merupakan salah satu e-library akademisi Indonesia yang memakai PDF sebagai ekstensi file. Dataset yang digunakan dalam penelitian ini berasal dari portal GARUDA dengan data sebanyak 10000 yang terdiri dari 9800 benign, 196 malicious html, dan enam malicious pdf. Dataset dianalisis menggunakan VirusTotal, PDF-parser dan PDFid. Proses klasifikasi dilakukan sebanyak…
K-Means clustering is a method to grouping data based on the similarity of features and detect the hidden patterns in dataset. The dataset is from GARUDA Repository which contains raw data of PDF files. GARUDA dataset extraction process used static analysis method. The data extraction process produced twenty�one features using PDFiD. GARUDA dataset has a multi-class and imbalanced data, there…
The amount of Malware is constantly increasing. Most Malware is a modification of previous Malware data. The datasets used from CIC-MalMem-2022 are Benign and Spyware-CWS. This study used the Naïve Bayes Classifier algorithm. Naïve Bayes is one of the classification algorithms that has accuracy in making predictions and has a good reputation in classification, especially in learning speed com…
In the security sector, malware that specifically attacks smartphones is growing faster and more sophisticated. Malware is becoming more and more powerful in carrying out criminal acts, such as stealing and destroying important data and information stored on mobile phones, thus demanding the creation of an anti-malware system that can prevent and detect when carrying out malware attacks on smar…
Portable Document Format (PDF) is a document exchange media that is very vulnerable to malicious attacks, namely Malware PDF. One of the services that most often use PDF files as a medium is a scientific publication service Garba Rujukan Digital (GARUDA). Therefore, research was conducted using static analysis methods for each PDF and data extraction using PDFiD. Based on these research, it fou…
The Portable Document Format (PDF) is one of the most commonly used document reader formats, the object structure in PDF is flexible and easy to use. Therefore, that hackers use PDFs to carry out the attacks. The dataset comes from the Garba Rujukan Digital (GARUDA), which consists of a collection of PDF files. PDF files will extract using the pdfid tools to get features used in the multiclass …
Virus, trojan, dan semua komplotannya meupakan program jahat yang selalu mempunyai tujuan untuk menghancurkan, merusak data serta sistem komputer dan Android yang kita miliki. Virus tidak pernah pilih kasih, tidak pandang bulu, dan tidak mempunyai bebas kasihan sedikit pun. Untuk itu, jangan sampai semua itu terjadi dan menimpa pada diri Anda. Bentengi segera komputer, laptop, Android, dan s…
The internet is a liaison between one electronic media and other electronic media quickly and accurately in acommunication network. Where the communication network sends information that is transmitted by signaling at an adjusted frequency[3]. Adware is software that is used to display advertisements for monetary gain[6]. The dataset comes from the Canadian Institute for Cybersecurity (CIC) wit…
Visualization is a method used to represent data in the form of an image to display hidden information. The visualization in this study uses malware data to be converted into a grayscale image. This study uses 10 types of malware with a total of 1000 data. The test data is divided into training data as much as 80% of the test data is 20% of the total data. Malware is tested using Local Binary P…