Indonesi
an
Journa
l
of El
ect
ri
cal Engineer
ing
an
d
Comp
ut
er
Scie
nce
Vo
l.
23
,
No.
3
,
Septem
ber
2021
, pp.
1643
~
1653
IS
S
N: 25
02
-
4752, DO
I: 10
.11
591/ijeecs
.v
23
.i
3
.
pp
1643
-
1653
1643
Journ
al h
om
e
page
:
http:
//
ij
eecs.i
aesc
or
e.c
om
Vuln
erab
ility and
risk as
sess
m
ent
for ope
rating
sys
tem (OS
)
with fra
mework
STRIDE
: compa
riso
n b
etween Vu
lnOS
and
Vuln
ix
Ad
it
yas Wid
j
ajarto
,
M
uh
ar
man
L
ubis
,
V
resel
iana A
yuni
ng
t
yas
Depa
rtment
o
f
I
nform
at
ion
S
y
s
t
em,
School
of
In
dustria
l
Engi
n
eering,
Telkom
Univer
sit
y
,
Indon
esia
Art
ic
le
In
f
o
ABSTR
A
CT
Art
ic
le
history:
Re
cei
ved
Oct
27, 202
0
Re
vised Jul
28,
2021
Accepte
d Aug
4,
2021
The
rap
id
dev
elopm
ent
of
informati
on
te
chno
lo
g
y
has
m
ade
sec
urity
b
ec
om
e
ext
remel
y
.
Apar
t
from
ea
s
y
acc
ess,
the
re
are
als
o
thre
at
s
to
vu
l
ner
abilities,
with
the
num
ber
of
c
y
b
er
-
a
tt
a
cks
in
2019
show
ed
a
tot
a
l
of
1,
494
,
281
aro
und
the
world
issued
b
y
th
e
n
at
io
n
al
c
y
b
er
and
cr
y
pt
o
age
n
c
y
(BSS
N)
hone
y
ne
t
proje
c
t.
Thus,
v
ulne
rab
il
i
t
y
an
aly
sis
should
b
e
conduc
t
ed
to
pr
epa
re
wors
t
ca
se
sc
ena
r
io
b
y
antici
p
at
ing
wit
h
prope
r
str
ateg
y
fo
r
responding
the
atta
cks.
Actua
l
l
y
,
vuln
er
abi
lit
y
is
a
s
y
st
e
m
or
design
we
akne
ss
tha
t
is
used
when
an
int
rude
r
execut
e
s
comm
and
s,
ac
ce
ss
es
unau
tho
riz
ed
d
ata,
and
ca
rri
es
out
deni
a
l
of
service
at
t
ac
ks.
Th
e
stud
y
was
per
for
m
ed
using
the
Alie
nVaul
t
software
as
the
vulne
rab
il
i
t
y
assess
m
ent
.
The
re
sults
were
ana
l
ysed
b
y
the
form
ula
of
risk
e
stim
at
ion
equ
al
t
o
the
num
ber
of
vulne
rab
il
i
t
y
fou
nd
rel
a
te
d
to
the
thre
a
t.
Mea
nwhile,
thr
ea
t
is
obta
in
ed
from
ana
l
y
s
is
of
sam
ple
walkt
hroughs,
a
s
a
ref
er
ence
fo
r
fre
quent
expl
o
it
ation.
The
r
isk
esti
m
at
io
n
result
ind
ic
a
te
t
he
73
(seve
n
t
y
t
hre
e)
for
the
h
i
ghest
score
of
5
(five
)
t
y
pe
risks
ide
nti
fi
ed
while
later
on
,
it
is
used
for
re
-
anal
y
zi
ng
b
ase
d
on
the
spoofing,
ta
m
pe
ring,
rep
ud
ia
t
ion
,
informati
on
d
i
sclosure
,
den
ial
of
servic
e
,
and
eleva
t
ion
of
prvil
eg
e
(STRI
DE)
fra
m
ework
tha
t
indi
c
ated
t
he
net
work
func
ti
on
does
no
t
a
cc
om
m
odat
e t
he
ex
isti
ng
t
y
pes
o
f
risk
namel
y
s
poofing.
Ke
yw
or
ds:
Assesm
ent
Op
e
rati
ng syst
e
m
Ri
sk
Scan
ning
Vu
l
ner
a
bili
ty
This
is an
open
acc
ess arti
cl
e
un
der
the
CC
B
Y
-
SA
l
ic
ense
.
Corres
pond
in
g
Aut
h
or
:
Ad
it
ya
s
W
i
djaja
rto
Dep
a
rtm
ent o
f Info
rm
at
ion
Syst
e
m
Tel
ko
m
U
ni
versi
ty
Jln.
Tel
e
ko
m
unikasi
N
o.
1, Ba
ndung,
40257, I
ndonesi
a
Em
a
il
: adtwj
rt
@tel
ko
m
un
ive
rsity
.ac.id
1.
INTROD
U
CTION
The
de
velo
pme
nt
of
the
I
nte
rn
et
in
inf
or
m
at
ion
te
chnolo
gy
(I
T
)
is
devel
op
in
g
ve
ry
f
ast
al
on
g
with
the
gro
wth
of
i
ts
us
ers
.
Like
w
ise
,
the
le
vel
of
crim
e
in
inf
orm
at
ion
te
chnol
og
y
is detrim
e
ntal
to
it
s
us
er
s
,
both
ind
ivi
du
al
s
,
an
d
or
gan
iz
at
io
ns.
I
nfor
m
at
ion
secur
it
y
is
the
protect
ion
of
c
om
pu
te
r
eq
uipm
ent,
facil
it
ie
s
,
data
,
and
in
form
at
io
n
from
m
isuse
of
una
uthorize
d
or
un
a
uthor
i
zed
par
ti
es.
T
he
ro
le
of
in
for
m
at
ion
secur
it
y
fo
r
a
n
orga
nizat
ion
is
to
prov
i
de
inf
or
m
at
ion
prote
ct
ion
from
var
iou
s
t
hr
eat
s
in
order
to
e
nsure
bu
si
ness
co
ntinu
it
y,
reduce
busines
s
risks,
inc
rea
se
retu
rn
on
i
nv
e
stm
ent
(R
OI),
a
nd
inc
re
ase
business
oppo
rtu
ni
ti
es
[1]
,
[2
]
.
Inform
at
ion
se
cur
it
y
is
a
n
e
f
fort
to
antic
ip
at
e
fr
a
ud
th
r
ough
t
he
detect
ion
ste
p
by
st
ep
process
wit
hin
an
inf
or
m
at
ion
-
ba
sed
syst
e
m
reg
ard
le
ss
it
s
bounda
ry
and
li
m
i
ta
ti
on
.
The
as
pe
ct
s
that
m
us
t
be
m
e
t
in
a
sys
tem
to
ens
ur
e
i
nfor
m
at
ion
sec
ur
i
ty
ar
e
the
in
f
or
m
at
i
on
pro
vi
ded
is
accurate
a
nd
c
om
plete
as
the
rig
ht
or
ver
ifie
d
a
nd
validat
ed
i
nform
at
ion
,
w
hich
is
accounta
bl
e
or
held
by
the
rig
ht
pe
op
le
that
can
be
acce
ssed
a
nd
us
e
d
accor
ding
t
o
the
need
at
the
rig
ht
tim
e,
an
d
prov
i
des
i
nfor
m
at
ion
in
t
he
rig
ht
f
or
m
at
or
f
or
m
based
on
the
agr
eea
ble m
ann
er
.
Evaluation Warning : The document was created with Spire.PDF for Python.
IS
S
N
:
2502
-
4752
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci,
Vo
l.
23
, N
o.
3
,
Se
ptem
ber
20
21
:
1643
-
16
53
1644
Inform
at
ion
secur
it
y
m
anag
e
m
ent
is
an
act
i
vity
to
keep
in
form
ation
res
ources
sa
fe.
Ma
nag
em
ent
i
s
no
t
only
exp
e
ct
ed
to
keep
i
nfor
m
at
ion
res
ources
safe
,
but
al
so
exp
ect
ed
to
kee
p
the
i
m
ple
m
ented
syst
e
m
functi
onin
g
after
a
disaste
r
or
secur
it
y
syst
e
m
br
eaks.
T
he
sta
ges
in
inf
orm
at
ion
m
anage
m
ent
are
iden
ti
fyi
ng
threats
that
can
at
ta
ck
com
pan
y
info
rm
at
ion
r
eso
ur
ces
a
nd
t
hen
def
i
ning
th
e
risks
that
can
be
cause
d
by
these
threats.
Ne
xt
is
determ
ining
an
inf
o
rm
at
ion
secur
it
y
po
li
cy
and
im
ple
m
en
ti
ng
co
ntr
ols
to
address
these
risks.
Vu
l
ner
a
bili
ty
scann
i
ng
detect
s
an
d
ide
ntifie
s
know
n
issue
s
of
softwa
re
a
nd
to
ols
in
sta
ll
ed
on
t
he
host
s
uch
as
old
e
r
ve
rsions
of
t
he
s
of
twa
re
in
us
e
,
act
ive
protoc
ol
vulne
rab
il
it
ie
s,
an
d
sta
nd
a
rd
pass
w
ords.
This
act
i
vity
is
diff
ic
ult
to
do
m
anu
al
ly
;
hence
this
ph
ase
i
s
perform
ed
us
ing
an
a
uto
m
ated
too
l
w
hic
h
identifie
s
ope
n
ports
and
trie
s
var
i
ous
e
xp
l
oits
on
the
port
to
identify
if
a
pa
rtic
ular
proce
ss/sof
t
war
e
is
us
in
g
a
port
t
hat
i
s
vu
l
ner
a
ble
to
exp
l
oits
base
d
on
it
s
pr
ocess
.
S
om
e
of
the
too
ls
us
e
d
t
o
perform
vu
lne
rab
il
it
y
scann
i
ng
are
Ness
us
, O
penVas, an
d Q
ualy
s [
3].
In
2019
the
num
ber
of
vuln
erab
il
it
ie
s
incr
eased
by
17.
6%
by
20
[
4],
wh
ic
h
is
sup
porte
d
by
the
vu
l
ner
a
bili
ty
sta
ti
st
ic
s
release
d
by
Re
sear
ch
La
bs
:
a
pp
l
ic
at
ion
sec
ur
it
y
and
data
s
ecur
it
y.
I
nfo
r
m
at
ion
te
chnolo
gy
sec
ur
it
y
is
need
e
d
to
increase
e
ffi
ci
ency
in
cy
be
rsp
ace
secu
rity
,
m
on
it
or
in
g,
a
nd
a
naly
sin
g
threats
and
inci
den
ts
that
e
xist
in
inf
or
m
at
ion
t
echnolo
gy
sec
ur
it
y,
w
hic
h
t
he
functi
ons
t
hat
ca
n
be
use
d
is
vu
l
ner
a
bili
ty
scann
i
ng
t
o
detect
s
and
i
den
ti
fies
know
n
pr
oble
m
s
with
so
f
tware
a
nd
t
oo
l
s
instal
le
d
on
t
he
host
[3
]
. O
ne
w
ay
to
re
spo
nd quic
kly t
o protec
t t
he
I
T assets,
m
ai
ntain aw
a
re
ne
ss of e
nv
i
ron
m
ental
v
uln
e
ra
bili
ti
es,
and
m
i
ti
gate
pote
ntial
threats
is
to
us
e
it
sy
stem
at
ic
a
ll
y.
This
is
the
pr
oc
ess
f
or
ide
ntif
yi
ng
a
nd
m
eas
ur
i
ng
secur
it
y
vu
l
ne
rab
il
it
ie
s
in
t
he
orga
nizat
ion
'
s
env
i
ronm
ent
as
a
com
pr
ehen
sive
pro
gr
am
to
pr
ovide
orga
nizat
ion
s
with
the
know
le
dg
e,
awa
ren
e
ss,
an
d
risk
ba
ckgr
ound
to
unde
rstan
d
a
nd
respo
nd
a
gai
nst
the
env
i
ronm
ental
threats
.
Ba
se
d
on
the
bac
kgr
ound
desc
rib
ed
a
bove
,
se
ve
ral
pr
ob
le
m
s
to
be
re
so
l
ved
in
t
his
stud
y
can
be
f
or
m
ulate
d
by
si
m
ulati
ng
vu
l
ne
rab
il
it
y
scanni
ng
with
the
A
li
enV
ault
an
d
Qu
al
ys
(m
irro
r
ing
the
scenari
o)
s
of
t
war
e
on
t
he
V
ulnOS,
Vu
l
nix,
an
d
direct
cu
rr
e
nt
-
1
(
DC
-
1)
(f
or
the
pur
pose
of
sh
a
dow
ing
th
e
resu
lt
)
operati
ng
syst
em
s
to
help
ide
ntify
vu
lnera
bili
ti
es.
Com
par
ison
of
t
he
re
su
lt
s
of
vulne
rab
il
it
y
scann
i
ng
in
Alie
nVault
and
Q
ualy
s
so
ftwar
e
a
nd
a
ri
sk
sc
or
e
gr
a
ph
can
hel
p
ident
ify
the
ty
pes
of
at
ta
cks
an
d
threats
that of
te
n
occ
ur. Mean
w
hile, the STRI
DE fra
m
ewo
r
k
an
al
ysi
s d
evel
op
e
d
by
Mi
cro
soft i
s to
analy
ze the thr
ea
t
at
ta
ck
on t
he w
al
kth
r
ough.
2.
RESEA
R
CH MET
HO
D
Actuall
y,
threa
t
can
be
def
in
ed
as
the
at
tem
pt
to
exp
loit
the
ben
efit
from
the
secur
it
y
weak
nes
s
e
s
within
certai
n
inf
or
m
at
ion
based
syst
e
m
fo
r
certai
n
per
io
d
of
tim
e,
wh
ic
h
i
m
plica
te
d
to
the
neg
at
ive
im
pac
t
for
the
en
vir
onm
ent
in
the
sh
ort
an
d
lo
ng
run.
T
her
e
f
or
e
,
it
can
com
e
fr
om
two
m
ain
sou
rces,
wh
i
ch
are
hu
m
ans
bo
t
h
exter
nal
and
int
ern
al
as
well
throu
gh
nat
ur
al
threats
nam
el
y
earth
qu
a
kes,
hurric
anes
,
flo
ods
,
an
d
fires
[
5].
Me
an
wh
il
e,
ris
k
is
de
fine
d
as
the
pote
ntial
loss,
dam
age,
or
dam
age
to
asset
s
a
s
a
resu
lt
of
th
reats
exp
l
oiti
ng
vu
l
ne
rab
il
it
ie
s
su
ch
as
fina
ncial
loss,
loss
of
pr
i
va
cy
,
dam
age
to
reputat
ion,
le
ga
l
i
m
plica
t
ion
s
,
an
d
even
loss
of
li
f
e.
It
ca
n
al
so
be
de
fine
d
as
th
e
res
ult
of
m
ulti
plica
ti
on
bet
ween
vul
ner
a
bi
li
t
y
and
th
reats.
O
n
the o
the
r han
d, pen
et
rati
on
tes
ti
ng
ensu
res
th
at
the test
created is m
at
eria
li
z
ed
or com
plete
d.
Give
n
that i
s
p
art
of
a
la
r
ger
sec
ur
it
y
program
,
on
e
m
us
t
inclu
de
othe
r
safety
char
act
erist
ic
s
to
al
ign
the
te
st
with
dem
and
as
a
dr
i
ver
[
6].
A
vulne
rab
il
it
y
m
achine
is
an
operati
ng
syst
em
crea
te
d
with
weak
sec
ur
it
y
vu
lne
ra
bili
ti
es
and
i
s
us
ua
ll
y
us
ed
f
or
at
te
m
pted
at
ta
cks.
V
ulnO
S
is
a
su
it
e
of
vu
l
ner
a
ble
ope
rati
ng
syst
em
s
pack
a
ge
d
in
a
virtu
al
i
m
age
to
i
m
pr
ov
e
pe
netrati
on
te
sti
ng
.
V
ulnOS
wa
s
create
d
by
the
a
utho
r
id
with
the
nam
e
c4b
3rw
0lf
,
wit
h
the
Lin
ux
ba
se
operati
ng
syst
e
m
and
ca
n
be
dow
nlo
a
de
d
on
the
V
ulnhub
web
sit
e
[4
]
.
V
uln
e
rab
le
li
nu
x
hosts
with
c
onfig
ur
a
ti
on
flaws.
V
ul
nix
is
m
ade
wi
th
the
nam
e
Hack
L
AB:
V
ulni
x
an
d
c
reated
by
the
us
e
r
id
rebo
ot
us
er
,
with
the
basic
operati
ng
syst
e
m
Ub
untu
ser
ve
r
12.
04
a
nd
ca
n
be
down
l
oad
e
d
on
the
vuln
hub
web
sit
e
wh
il
e
DC
-
1
is
a
vulnera
ble
m
achine
t
hat
is
deliberatel
y
cr
eat
ed
f
or
t
he
pur
pose
of
gaini
ng
ex
per
ie
nce
in
the
world
of
pe
net
rati
on
te
sti
ng.
DC
-
1
is
m
ade
by
DC
AU
aut
hor
i
d
with
the
nam
e
DC:
1,
with
t
he
De
bia
n
32
bit
op
e
rati
ng syst
e
m
an
d
can
be d
ownloa
de
d on
the vuln
hub w
ebsite
.
STRIDE
is
a
m
od
el
-
based
t
hr
eat
m
od
el
in
g
te
c
hn
i
qu
e
de
velo
ped
by
m
ic
ro
soft
that
al
so
guides
secur
it
y
analy
s
is
throu
gh
the
act
ivit
ie
s
that
m
us
t
be
carrie
d
out
f
or
the
proces
s
to
b
e
ef
fecti
ve.
Si
x
ty
pes
of
secur
it
y
threats
inclu
de
s
poof
i
ng
at
ta
cks
occ
ur
w
hen
a
n
at
t
acker
pret
en
ds
to
be
s
om
eon
e
they
are
no
t
[7
]
-
[
9].
It
is
ty
pical
ly
us
ed
to
gain
acc
ess
to
a
ta
r
get'
s
per
s
onal
inf
or
m
at
ion
,
w
hich
sp
rea
ds
m
al
war
e
via
i
nf
ect
ed
li
nk
s
or
at
ta
chm
ents,
bypasses
net
w
ork
acce
ss
co
nt
ro
ls,
or
re
distr
ibu
te
s
traf
fic
to
carry
out
at
ta
cks
[
10
]
-
[
14]
.
The
n,
tam
per
ing
occ
ur
s
w
hen
at
ta
cker
s
m
od
ify
or
edit
offici
al
inf
or
m
at
ion
an
d
re
pudiati
on
occurs
at
the
tim
e
of
so
m
eon
e
ex
ec
ute
certai
n
a
ct
ion
w
hile
la
te
r
o
n
try
t
o
cl
a
i
m
the
oth
er
w
ise
.
It
usual
ly
com
es
down
to
the
sp
eci
fic
act
ivit
y
pr
ocess
s
uch
as
cred
it
card
transacti
ons
w
her
e
use
rs
bu
y
so
m
e
thing
an
d
then
cl
ai
m
they
did
no
t
t
o
ob
ta
i
n
c
ertai
n
ben
e
fit
[
15
]
-
[
18
]
.
O
n
i
nfor
m
at
ion
disclosure,
data
breac
hes
or
una
uthorize
d
acce
ss
to
confide
ntial
inform
ation
an
d
den
ia
l
of
ser
vice
(DoS)
relat
ed
to
creati
ng
serv
ic
e
inter
r
upti
ons
for
le
gitim
at
e
us
ers
a
nd
m
os
t
rece
ntly
relat
ed
to
el
evati
on
of
pri
vilege
to
gain
hi
gh
e
r
pr
i
vileged
acce
ss
to
syst
em
el
e
ments
Evaluation Warning : The document was created with Spire.PDF for Python.
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci
IS
S
N:
25
02
-
4752
Vuln
er
abil
it
y and ri
sk
as
sess
men
t f
or
opera
ti
ng
s
yst
e
m
(
O
S)
wi
th fram
ew
or
k
…
(
Adity
as
Wi
dja
jart
o
)
1645
by
us
ers
with
li
m
i
te
d
auth
or
it
y.
On
the
ot
her
hand,
inter
net
protoc
ol
(
IP
)
a
s
a
data
ro
utin
g
prot
oco
l
is
the
ke
y
to
the
co
nv
e
rgence
with
ho
m
og
e
ne
ous
an
d
flat
interco
nn
e
ct
ion
proce
sse
s
with
a
si
m
ple
syst
e
m
design
can
le
ad
to
the
l
ower
net
work
m
anag
em
ent
cost
s
[19]. N
et
w
ork
de
velo
pm
ent
hubs
a
re
ass
oc
ia
te
d
with
m
obil
ity
to
ens
ur
e
netw
or
k
a
vaila
bili
ty
fo
r
co
nnect
ed
e
ntit
ie
s
in
m
oti
on
an
d
res
ourc
es
in
st
or
a
ge
a
nd
com
pu
te
volum
es,
especial
ly
in
par
al
le
l
com
pu
ti
ng,
net
work
com
pu
ti
ng
,
a
nd
cl
oud
c
ompu
ti
ng,
w
hich
in
the
en
d
s
houl
d
b
e
protect
ed
a
nd
m
ai
ntaned
i
n
a
t al
l cost [
20
]
-
[
24]
.
At
the
re
view
sta
ge,
ide
ntific
at
ion
will
be
c
arr
ie
d
out
by
de
sign
i
ng
t
o
de
s
cribe
the
pla
nning
to
so
l
ve
the
pro
blem
.
T
he
nee
ds
us
e
d
in
this
researc
h
are
the
vulne
rab
le
m
achine
op
e
rati
ng
syst
em
s
Vu
ln
OS
,
V
ul
ni
x
and
DC
-
1
,
a
nd
the
s
of
t
war
e
us
e
d
are
Alie
nV
a
ult
an
d
Qu
al
ys.
Me
a
nwhile
,
at
the
data
colle
ct
ion
sta
ge
,
execu
ti
on
will
be
car
ried
ou
t
with
a
va
riable
m
achine
an
d
r
el
at
ed
so
ft
ware,
then
vulnera
bili
ty
scann
in
g
will
be
ca
rr
ie
d
ou
t
and
the
colle
ct
ed
data
will
be
obta
ine
d
the
n
us
e
d
f
or
r
esear
ch
a
naly
sis.
At
the
a
naly
sis
st
age
,
the
outp
ut
vuln
erab
il
it
y
scanni
ng
will
be
car
ried
ou
t
on
Alie
nV
a
ult
an
d
Q
ualy
s
to
ide
ntif
y
the
ty
pes
of
t
hr
ea
t
at
ta
cks
that
hav
e
bee
n
coll
ect
ed
durin
g
the
colle
ct
ion
sta
ge.
The
dat
a
ob
ta
in
e
d
is
then
car
ried
out
by
cal
culat
ing
t
he
risk,
wh
ic
h
will
be
a
naly
zed
base
d
on
t
he
STR
IDE
f
r
a
m
ewo
r
k.
I
n
t
he
fi
nal
sta
ge
,
the
interp
retat
ion
will
con
sist
of
a
con
cl
us
i
on
on
the
researc
h
that
has
bee
n
done
a
nd
sugg
e
sti
on
s
th
at
can
be
giv
e
n
f
r
om
the
res
ults
of
ris
k
analy
sis
on
vulne
rab
le
m
achines
us
i
ng
t
he
vulnera
bili
ty
scan
ning
f
eat
ur
e
on
Alie
nV
a
ult a
nd Qualy
s.
The
fo
ll
owin
g
T
able
s
1
a
nd
2
is
an
ex
planati
on
of
t
he
hard
war
e
sp
eci
ficat
ion
a
nd
s
of
t
wa
re
f
unct
ions
us
e
d,
incl
ud
i
ng
W
i
ndows
10
Enter
pr
ise
,
an
op
e
rati
ng
syst
e
m
that
pr
ovi
de
s
al
l
the
featu
res
of
W
i
ndows
10
Pr
o,
with
a
dd
i
ti
on
al
featu
res
to
help
inf
or
m
at
ion
te
chnolog
y
(
IT
-
base
d
)
organ
iz
at
io
ns
.
W
i
ndows
10
in
this
case,
is
us
e
d
a
s
the
operati
ng
syst
em
on
t
he
m
ai
n
hard
war
e
.
Me
an
w
hi
le
,
Deb
ia
n
as
a
com
pu
te
r
op
e
rati
ng
syst
e
m
co
m
posed
of
s
of
twa
r
e
pac
kages
release
d
as
f
ree
a
nd
ope
n
s
of
t
w
are
under
the
m
ajo
rity
li
cens
e
of
the
GNU
gen
e
ral
public
li
cense
and
ot
her
fr
ee
so
ft
war
e
li
cen
s
es.
I
n
this
a
nal
ysi
s,
Deb
ia
n
is
us
e
d
as
t
he
op
erati
ng
syst
e
m
on
VirtualBo
x
on
w
hich
Al
ie
nV
a
ult
is
base
d.
Me
a
nwhile
,
U
buntu
is
an
op
e
n
sour
ce
operati
ng
sy
stem
distrib
uted
Lin
ux
base
d
on
Deb
ia
n
a
nd
ha
s
a
de
sk
t
op
i
nterf
ace
.
In
t
hi
s
analy
sis,
U
buntu
is
use
d
as
th
e
op
e
rati
ng
syst
e
m
on
Virtual
Box
on
w
hic
h
V
ulnOS
is
base
d,
a
serie
s
of
vulne
ra
ble
o
pe
rati
ng
s
yst
e
m
s
pack
a
ge
d
in
virtu
al
im
ages
a
nd
us
e
d
to
im
pr
ove
pe
netrati
on
te
sti
ng
s
kill
s.
Vu
l
nOS
is
us
e
d
as
an
obj
ect
t
hat
is
analy
zed
by
ea
ch
of
the
open
so
urce
SI
EM
too
ls.
Vu
l
nix
is
a
Linu
x
host
that
is
vu
lner
able
to
co
nf
ig
ur
at
i
on
flaws.
T
he
DC
-
1
is
a
vu
l
ner
a
ble
m
achine
de
sign
e
d
for
t
he
pur
pose
of
ga
ining
e
xp
e
rience
in
the
w
orl
d
of
pen
et
rati
on
te
s
ti
ng
.
VirtualB
ox
is
virtu
al
iz
at
ion
softwa
re
that
can
be
use
d
to
e
xecu
te
add
it
io
nal
op
erati
ng
syst
e
m
s
within
the
m
ai
n
op
e
r
at
ing
syst
em
.
In
this
a
naly
sis,
Virtua
lB
ox
is
instal
le
d
on
W
indows
10
a
nd
us
e
d
to
r
un
se
ve
ral
op
e
rati
ng
syst
em
s.
Alie
nV
aul
t
is
a
com
pr
eh
ensive
sec
uri
ty
syst
e
m
that
includes
open
source
from
detect
ion
to
ge
ne
rati
ng
m
et
rics
and
re
ports
to
t
he
e
xe
cutive
le
vel.
I
n
this
a
naly
sis,
Alie
nVault
is
us
e
d
to
analy
ze the
vu
l
ner
a
bili
ty
o
f
ea
ch vu
l
ner
a
ble
m
achine. Qu
al
ys i
s a co
m
m
er
ci
al
scann
e
r w
eb
a
pp
li
cat
ion,
wh
ic
h
can
be
us
e
d
to
find,
ide
ntify
,
and
asse
ss
vu
lnera
bili
ti
es
so
they
can
be
pri
or
it
iz
ed
a
nd
f
ixed
befor
e
t
he
y
ar
e
ta
rg
et
ed
and e
xploit
ed by at
ta
cke
rs
.
Table
1.
Hard
war
e
sp
eci
ficat
ion
Co
m
p
o
n
en
t
Hardwar
e
Sp
ecif
icatio
n
Co
re
Hardwa
re
Sp
ecif
icatio
n
Proces
so
r
Intel® Co
re
™
i7
-
7
5
0
0
U du
al
-
co
re
2
.7GHz (8 CP
Us),
~
2.9
GHz
Me
m
o
r
y
8
1
9
2
MB RAM
Hard Disk
1
T
B
Sy
ste
m
T
y
p
e
64
-
b
it Operatin
g
Sy
ste
m
,
x6
4
-
b
ased
p
rocess
o
r
Op
erating
Sy
ste
m
W
in
d
o
ws 1
0
E
n
ter
p
rise 64
-
b
it (
1
0
,
B
u
ild
17
1
3
4
)
1
st
VM
Vir
tu
alBo
x
sp
ecif
icatio
n
Proces
so
r
Intel® Co
re
™
i7
-
7
5
0
0
U du
al
-
co
re
2
.7GHz (1 CP
Us),
~
2.9
GHz
Me
m
o
r
y
4
0
9
6
MB RAM
Hard Disk
3
2
GB
Sy
ste
m
T
y
p
e
64
-
b
it Operatin
g
Sy
ste
m
Op
erating
Sy
ste
m
Deb
ian
GNU/
Linu
x
8 (jessie) 64
-
b
it
2
nd
VM
VirtualB
o
x
sp
ecif
icatio
n
Proces
so
r
Intel® Co
re
™
i7
-
7
5
0
0
U du
al
-
co
re
2
.7GHz (8 CP
Us),
~
2.9
GHz
Me
m
o
r
y
7
8
6
M
B
Hard Disk
3
2
GB
Sy
ste
m
T
y
p
e
64
-
b
it Operatin
g
Sy
ste
m
Op
erating
Sy
ste
m
Ub
u
n
tu
1
4
.0
4
.6 LT
S 64
-
b
it /
Vu
ln
O
S v2
3
rd
VM
VirtualB
o
x
sp
ecif
icatio
n
Proces
so
r
Intel® Co
re
™
i7
-
7
5
0
0
U du
al
-
co
re
2
.7GHz (8 CP
Us),
~
2.9
GHz
Me
m
o
r
y
5
1
2
M
B
Hard Disk
3
2
GB
Sy
ste
m
T
y
p
e
64
-
b
it Operatin
g
Sy
ste
m
Op
erating
Sy
ste
m
Ub
u
n
tu
Ser
v
er
1
2
.04
86
x
b
it /
Vu
ln
ix
4
th
V
M
Vi
rtualB
o
x
sp
ecif
icatio
n
Proces
so
r
Intel® Co
re
™
i7
-
7
5
0
0
U du
al
-
co
re
2
.7GHz (8 CP
Us),
~
2.9
GHz
Me
m
o
r
y
5
1
2
M
B
Hard Disk
3
2
GB
Sy
ste
m
T
y
p
e
64
-
b
it Operatin
g
Sy
ste
m
Op
erating
Sy
ste
m
Deb
ian
86
x
b
it /
DC
-
1
Evaluation Warning : The document was created with Spire.PDF for Python.
IS
S
N
:
2502
-
4752
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci,
Vo
l.
23
, N
o.
3
,
Se
ptem
ber
20
21
:
1643
-
16
53
1646
Table
2
.
Softw
are s
pecifica
ti
on
Ty
p
e
So
f
tware
Versio
n
Op
erating
Sy
ste
m
W
in
d
o
ws 1
0
E
n
ter
p
rise 64
-
b
it
1
0
,
Bu
ild
17
1
3
4
Deb
ian
8
Jess
ie 64
-
b
it
Ub
u
n
tu
1
4
.04
.6 LT
S 64
-
b
it
Vu
ln
erability
Op
er
atin
g
Sy
ste
m
Vu
ln
OS
2
Viln
ix
1
DC
-
1
1
Virtual
Machin
e
VirtualB
o
x
6
.1.2
So
f
tware
Alien
Vau
lt
5
.7.4
Qu
aly
s
-
T
h
e
S
T
R
I
D
E
t
h
r
e
a
t
m
o
d
e
l
c
a
t
e
g
o
r
i
z
e
s
t
h
r
e
a
t
s
b
a
s
e
d
o
n
s
p
o
o
f
i
n
g
,
t
a
m
p
e
r
i
n
g
,
r
e
p
u
d
i
a
t
i
o
n
,
i
n
f
o
r
m
a
t
i
o
n
d
i
s
c
l
o
s
u
r
e
a
n
d
e
l
e
v
a
t
i
o
n
o
f
p
r
i
v
i
l
e
g
e
.
E
a
c
h
o
f
t
h
e
s
i
x
t
h
r
e
a
t
c
l
a
s
s
i
f
i
c
a
t
i
o
n
s
i
s
a
m
e
t
h
o
d
o
f
a
t
t
a
c
k
t
h
a
t
c
a
n
e
x
p
l
o
i
t
t
h
e
i
n
f
o
r
m
a
t
i
o
n
a
s
s
u
r
a
n
c
e
c
om
p
o
n
e
n
t
a
n
d
e
a
c
h
h
a
s
t
h
e
s
e
c
u
r
i
t
y
p
r
o
p
e
r
t
i
e
s
o
f
a
n
o
f
f
i
c
e
r
t
o
d
e
a
l
w
i
t
h
t
h
e
t
h
r
e
a
t
.
T
h
e
i
d
e
n
t
i
f
i
e
d
v
u
l
n
e
r
a
b
i
l
i
t
i
e
s
a
n
d
t
h
r
e
a
t
s
a
r
e
t
h
e
n
a
n
a
l
y
z
e
d
h
o
w
t
h
e
t
h
r
e
a
t
s
w
i
l
l
d
i
r
e
c
t
l
y
a
f
f
e
c
t
e
a
c
h
a
s
s
e
t
o
w
n
e
d
[
2
5
]
.
T
h
e
r
e
a
r
e
s
i
x
s
e
c
u
r
i
t
y
ob
j
e
c
t
i
v
e
s
m
a
i
nt
a
i
n
e
d
,
n
a
m
e
l
y
c
o
n
f
i
d
e
n
t
i
a
l
i
t
y
,
i
n
t
e
g
r
i
t
y
,
a
v
a
i
l
a
b
i
l
i
t
y
,
a
ut
h
e
n
t
i
c
i
t
y
,
s
e
c
u
r
e
l
i
f
e
c
y
c
l
e
,
a
n
d
n
o
n
-
r
e
p
u
d
i
a
t
i
o
n
.
T
h
e
r
i
s
k
o
f
e
a
c
h
e
l
e
m
e
nt
w
i
l
l
d
e
p
e
n
d
o
n
t
h
e
t
y
p
e
o
f
a
t
t
a
c
k
c
a
r
r
i
e
d
o
u
t
.
U
s
i
n
g
t
h
i
s
i
n
f
o
r
m
a
t
i
o
n
a
n
d
k
n
o
w
l
e
d
g
e
o
f
t
h
e
p
o
t
e
n
t
i
a
l
s
e
v
e
r
i
t
y
o
f
t
h
e
a
t
t
a
c
k
,
w
e
c
a
n
d
e
t
e
r
m
i
n
e
t
h
e
r
i
s
k
s
c
o
r
e
.
I
n
t
h
e
p
i
c
t
u
r
e
b
e
l
o
w
,
i
t
i
s
e
x
p
l
a
i
n
e
d
t
h
a
t
t
h
e
t
op
o
l
o
g
y
i
n
t
h
i
s
s
t
u
d
y
c
o
n
s
i
s
t
s
of
1
r
o
u
t
e
r
c
o
n
n
e
c
t
e
d
t
o
t
h
e
i
n
t
e
r
n
e
t
,
1
l
a
p
t
o
p
h
o
s
t
,
1
s
o
f
t
w
a
r
e
o
n
t
h
e
s
e
r
v
e
r
,
a
n
d
3
v
u
l
n
e
r
a
b
l
e
m
a
c
hi
n
e
s
n
a
m
e
l
y
V
u
l
n
O
S
,
V
u
l
n
i
x
,
D
C
-
1
w
h
i
l
e
t
he
l
a
t
t
e
r
i
s
n
o
t
s
h
o
w
n
i
n
t
h
i
s
s
t
u
d
y
b
ut
u
s
e
d
f
o
r
s
h
a
d
o
w
e
x
p
e
r
i
m
e
nt
.
I
n
t
e
r
n
e
t
r
o
u
t
e
r
i
s
c
o
n
n
e
c
t
e
d
t
o
t
h
e
h
o
s
t
l
a
p
t
o
p
t
h
a
t
h
a
s
V
i
r
t
u
a
l
B
ox
i
n
s
t
a
l
l
e
d
.
T
h
e
i
n
t
e
r
n
e
t
r
o
u
t
e
r
p
r
o
v
i
d
e
s
a
n
I
P
a
d
d
r
e
s
s
w
h
i
c
h
i
s
u
s
e
d
a
s
a
l
i
n
k
b
e
t
w
e
e
n
t
h
e
A
l
i
e
n
V
a
u
l
t
a
n
d
Q
u
a
l
y
s
s
o
f
t
w
a
r
e
a
n
d
v
u
l
n
e
r
a
b
l
e
m
a
c
h
i
n
e
s
o
n
t
h
e
s
a
m
e
n
e
t
w
o
r
k
.
F
i
g
u
r
e
1
s
h
o
w
s
t
h
e
n
e
t
w
o
r
k
t
o
p
o
l
o
g
y
,
w
h
i
c
h
i
n
f
l
u
e
n
c
e
s
i
gn
i
f
i
c
a
nt
l
y
t
h
e
o
u
t
p
u
t
o
f
t
h
e
v
u
l
n
e
r
a
b
i
l
i
t
y
a
s
s
e
s
s
m
e
nt
o
n
A
l
i
e
n
V
a
u
l
t
a
s
a
r
i
s
k
f
a
c
t
o
r
f
o
r
e
a
c
h
v
u
l
n
e
r
a
b
i
l
i
t
y
f
o
u
n
d
w
i
t
h
i
n
t
h
e
s
y
s
t
e
m
,
w
h
i
c
h
i
s
i
n
a
c
c
o
r
d
a
n
c
e
w
i
t
h
t
h
e
c
om
m
o
n
v
u
l
n
e
r
a
b
i
l
i
t
y
s
c
o
r
i
n
g
s
y
s
t
e
m
(
C
V
S
S
)
v
3
.
0
p
r
o
v
i
d
e
d
b
y
t
h
e
n
a
t
i
o
n
a
l
v
u
l
n
e
r
a
b
i
l
i
t
y
d
a
t
a
b
a
s
e
(
N
V
D
)
a
s
c
a
n
b
e
s
e
e
n
i
n
T
a
b
l
e
3
.
C
V
S
S
i
s
a
s
t
a
n
d
a
r
d
I
T
v
u
l
n
e
r
a
b
i
l
i
t
y
s
c
o
r
e
,
a
n
d
t
h
i
s
m
e
t
h
o
d
p
r
o
v
i
d
e
s
a
s
c
o
r
e
r
a
n
g
i
n
g
f
r
o
m
0
t
o
1
0
.
T
h
e
c
o
m
m
o
n
v
u
l
n
e
r
a
b
i
l
i
t
y
s
c
o
r
i
n
g
s
y
s
t
e
m
(
C
V
S
S
)
p
r
o
v
i
d
e
s
a
w
a
y
t
o
c
a
p
t
u
r
e
t
h
e
m
a
i
n
c
h
a
r
a
c
t
e
r
i
s
t
i
c
s
o
f
v
u
l
n
e
r
a
b
i
l
i
t
i
e
s
a
n
d
g
e
n
e
r
a
t
e
a
n
um
e
r
i
c
a
l
s
c
o
r
e
t
h
a
t
r
e
f
l
e
c
t
s
t
h
e
i
r
s
e
v
e
r
i
t
y
.
T
h
e
n
um
e
r
i
c
a
l
s
c
o
r
e
s
c
a
n
t
h
e
n
b
e
t
r
a
n
s
l
a
t
e
d
i
nt
o
q
u
a
l
i
t
a
t
i
v
e
r
e
pr
e
s
e
n
t
a
t
i
o
n
s
(
s
u
c
h
a
s
l
o
w
,
m
o
d
e
r
a
t
e
h
i
g
h
,
a
n
d
s
e
r
i
o
u
s
)
t
o
h
e
l
p
o
r
g
a
n
i
z
a
t
i
o
n
s
p
r
o
p
e
r
l
y
a
s
s
e
s
s
a
n
d
p
r
i
o
r
i
t
i
z
e
t
he
i
r
v
u
l
n
e
r
a
b
i
l
i
t
y
m
a
n
a
g
e
m
e
n
t
p
r
o
c
e
s
s
e
s
.
Figure
1.
Net
w
ork
t
opology
Table
3
.
Seve
ri
ty
r
an
ge
Sever
ity
v3
Score
R
ange
None
0.
0
Low
0.
1
-
3.
9
Medium
4.
0
-
6.
9
High
7.
0
-
8.
9
Serious
9.
0
-
10.
0
Evaluation Warning : The document was created with Spire.PDF for Python.
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci
IS
S
N:
25
02
-
4752
Vuln
er
abil
it
y and ri
sk
as
sess
men
t f
or
opera
ti
ng
s
yst
e
m
(
O
S)
wi
th fram
ew
or
k
…
(
Adity
as
Wi
dja
jart
o
)
1647
3.
RESU
LT
S
A
ND
D
IS
C
USS
ION
3.1.
E
xp
eri
m
ent Vuln
Os wi
th
Alie
nVault
Table
4
repres
ents
the
nu
m
ber
of
vulne
ra
bili
ti
es
detect
ed
on
Vu
l
nOs
sca
nned
us
in
g
Alie
nV
a
ult
with
the
nu
m
ber
de
te
ct
ed
we
re
3
vu
l
ner
a
bili
ti
es
with
m
ediu
m
seve
rity
,
1
vulne
rab
il
it
y
wi
th
high
se
ver
it
y
an
d
fou
nd
23
in
f
o,
wh
il
e Fig
ur
e
2 shows its visua
li
zat
ion
. Th
e
re
fore,
A
1
in
here shows
the ty
pes
of vulne
ra
bili
ti
e
s
that
wer
e
f
ound
w
hen
sca
nn
i
ng,
nam
el
y
drup
al
co
re
crit
ic
al
re
m
ote
code
execu
ti
on
wi
th
script
I
D
108438,
CVSS
7.5,
po
rt
80,
an
d
se
ve
rity
in
the
hi
gh
cat
eg
or
y.
This
host
r
uns
dru
pal
a
nd
is
vulne
rab
le
t
o
co
de
vu
l
ner
a
bili
ti
es
for
rem
ote
acce
ss.
Me
an
w
hile,
A
2
s
hows
t
he
ty
pes
of
vulnera
bili
ti
es
fo
und
wh
il
e
sca
nn
i
ng,
nam
ely
SSH
w
eak
e
ncr
ypti
on
al
gorithm
s
su
pport
ed
with
s
cript
I
D
105611,
C
VS
S
4.3,
port
22,
an
d
m
edium
sever
it
y. T
he r
e
m
ote secur
e
s
hell co
nn
ect
io
n (SS
H) ser
ve
r
i
s conf
i
gured to
all
ow
wea
k
en
crypti
on alg
or
i
thm
s.
The
vu
l
ner
a
bili
ty
exists
in
S
SH
m
essages
wh
ic
h
us
e
ci
pher
-
bl
ock
chai
ning
(CBC
)
m
od
e
w
hich
al
l
ow
s
an
at
ta
cker
to
rec
ov
e
r
plainte
xt
from
ci
ph
ertex
t
blo
c
ks
.
O
n
th
e
oth
e
r
hand,
A3
sho
ws
the
ty
pes
of
vu
l
nerabil
it
ie
s
fou
nd
w
he
n
s
cann
i
ng,
nam
e
ly
SSH
wea
k
m
essage
a
uth
e
ntica
ti
on
c
ode
(MAC
)
al
gorithm
s
su
pport
ed
wit
h
script
I
D
1056
10,
CV
SS
2.6,
port
22,
a
nd
m
edium
sever
it
y.
The
rem
ote
SSH
ser
ver
is
config
ur
e
d
t
o
al
low
weak
MD
5
a
nd
96
-
bit
M
AC
al
gorithm
s.
Ther
e
fore,
A
4
sh
ows
the
ty
pe
s
of
vu
l
ner
a
bi
li
t
ie
s
found
whe
n
scan
ning,
nam
el
y
TCP
tim
est
a
m
ps
with
scr
ipt
ID
8009
1,
CVSS
2.6,
a
nd
m
edium
sever
it
y.
The
rem
ote
ho
st
i
m
ple
m
ents TCP tim
est
a
m
ps
which all
ow it
to be
us
e
d
to
c
al
culat
e uptim
e
.
Table
4
.
First e
xp
e
rim
ent sev
e
rity
r
an
ge wit
h Ali
enV
a
ult
Script ID
Vu
ln
I
D
Vu
ln
erability
CVSS
Sev
erity
1
0
8
4
3
8
V1
.A1
Drup
al core
c
ritica
l r
e
m
o
t
e cod
e exec
u
tio
n
7
,5
Hig
h
1
0
5
6
1
1
V1
.A2
SSH we
ak
encr
y
p
tio
n
algo
rith
m
s su
p
p
o
rted
4
,3
Mediu
m
1
0
5
6
1
0
V1
.A3
SSH we
ak
M
AC
a
lg
o
rith
m
s su
p
p
o
rte
d
2
,6
Mediu
m
8
0
0
9
1
V1
.A4
TCP ti
m
esta
m
p
s
2
,6
Mediu
m
Figure
2
.
V
ulnOS
vulne
rab
il
it
y wit
h Ali
enVault
3.2.
E
xp
eri
m
ent Vulni
x
w
it
h A
li
en
Vault
Table
5
repres
ents
the
num
ber
of
vulne
rab
il
it
ie
s
detect
ed
on
V
uln
i
x
scan
ne
d
us
i
ng
Alie
nVault
w
hile
F
igure
3
sho
w
it
s
visu
al
iz
at
ion.
I
n
this
ca
se,
the
nu
m
ber
detect
ed
we
r
e
14
vulne
rab
i
li
ti
es
with
m
e
diu
m
sever
it
y,
14
vu
lnera
bili
ti
es
with
hi
gh
se
ve
rity
,
2
vu
l
ner
a
bili
ti
es
with
serio
us
se
ver
it
y
an
d
f
ound
37
inf
o.
B
1
sh
ows
t
he
ty
pe
s
of
vuln
era
bi
li
t
ie
s
found
w
hen
scan
ning
,
nam
ely
OS
e
nd
of
li
fe
detec
ti
on
with
sc
rip
t
ID
103674, C
VS
S
1
0
,
a
nd ser
io
us ca
te
go
ry se
ve
rity
. Th
e opera
ti
ng
syst
em
o
n
rem
ote h
os
t ha
s r
eache
d
the e
nd
of
it
s
us
ef
ul
li
fe
and
sho
uld
not
be
us
e
d
a
gain
.
T
her
e
fore,
B
2
s
hows
the
ty
pes
of
vulne
ra
bili
ti
es
fo
un
d
wh
e
n
scan
ning,
nam
el
y
check
i
f
m
ai
lse
rv
er
ans
w
er
to
ve
rify
a
nd
e
xp
a
nd
requ
est
s
with
sc
ript
ID
10
0072,
C
VS
S
5,
port
25
,
a
nd
sever
it
y
hi
gh
cat
egory.
T
he
m
a
il
serv
er
on
this
host
a
nswers
VR
FY
and
E
XP
N
re
qu
e
sts
autom
at
ic
ally.
Me
anwhil
e,
B
3
s
hows
the
t
ypes
of
vulne
r
abili
ti
es
found
w
hen
sca
nn
i
ng,
nam
el
y
check
for
log
in
ser
vic
e
with
scri
pt
I
D
901202,
CVS
S
7.5,
port
513
,
a
nd
seve
rity
high
cat
eg
or
y
.
This
rem
ote
ho
st
is
run
ning
the
rl
ogin
ser
vice.
Rl
og
i
n
file
s
are
e
asy
to
a
buse
a
nd
c
ould
pote
nti
al
ly
al
low
any
on
e
to
lo
g
i
n
w
it
ho
ut
Evaluation Warning : The document was created with Spire.PDF for Python.
IS
S
N
:
2502
-
4752
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci,
Vo
l.
23
, N
o.
3
,
Se
ptem
ber
20
21
:
1643
-
16
53
1648
a
pass
w
ord.
B
4
s
hows
t
he
t
ypes
of
vu
l
nerabil
it
ie
s
t
hat
wer
e
f
ound
w
hen
scan
ni
ng,
nam
ely
check
for
r
s
h
serv
ic
e
with
sc
ript
I
D
100008
0,
C
VS
S
7.5,
port
51
4
,
a
nd
sever
it
y
cat
eg
ory
high.
This
r
e
m
ote
ho
st
run
s
the
rem
ote
sh
el
l
(
RSH)
ser
vice,
wh
ic
h
is
a
c
om
pu
te
r
pro
gr
a
m
that
can
exe
cute
s
hell
com
m
and
s
as
a
use
r
e
ven
with
an
ot
her
c
om
pu
te
r.
B
5
s
hows
t
he
ty
pe
s
of
vulne
rab
il
it
ie
s
fo
un
d
w
he
n
sca
nn
i
ng,
nam
el
y
fing
er
s
erv
ic
e
rem
ote
info
rm
at
ion
disclos
ur
e
vu
lne
ra
bili
ty
with
the
scrip
t
ID
802236,
CVSS
5,
port
79
,
an
d
seve
rity
in
the
high cate
go
ry.
These
hosts r
un f
i
ng
e
r
se
r
vices an
d
a
re vul
ne
rab
le
t
o
in
for
m
at
ion
d
isc
los
ur
e
vulne
rab
il
it
ie
s.
B6
sh
ows
t
he
ty
pe
s
of
vulne
rab
il
it
ie
s
fo
un
d
w
he
n
sca
nn
i
ng,
nam
el
y
secur
e
s
ock
et
la
ye
r
/t
ra
ns
po
rt
la
ye
r
se
cur
it
y
(
SSL/TL
S
)
:
O
penSSL
CC
S
m
an
in
the
m
i
dd
le
sec
ur
it
y
by
pass
vulne
rabi
li
t
y
with
scrip
t
ID
10
5042,
CVS
S
6.8,
port
995
,
a
nd
se
ver
it
y
hi
gh
cat
e
gory.
O
pe
nS
S
L
is
vulne
rab
le
t
o
bypas
s
secu
rity
vulne
rab
il
it
ie
s.
B7
s
hows
the
ty
pes
of
vulne
rab
il
it
ie
s
f
ound
wh
e
n
sc
ann
i
ng,
nam
ely
SSL/TLS:
Op
e
nSSL
T
LS
'
hear
tbeat
'
ext
ensio
n
inf
or
m
at
ion
disclosure
vulne
r
abili
ty
with
script
ID
10
5042,
CVSS
6.8
,
po
rt
993
,
a
nd
se
ve
rity
hig
h
cat
e
gory.
Op
e
nSSL
is
vulne
rab
le
to
by
pass
sec
ur
it
y
vulne
rab
il
it
ie
s.
B8
show
s
the
ty
pes
of
vu
l
nerabil
it
ie
s
fo
und
wh
e
n
scan
ning,
nam
el
y
transm
issio
n
co
ntr
ol
pro
tocol
(
TCP
)
ti
m
est
a
m
ps
with
sc
ript
ID
80
091,
CV
SS
2.6
,
a
nd
m
edium
cate
go
ry sev
e
rity
, wh
ic
h
the
host i
m
plem
ents TCP tim
est
a
m
ps
.
Table
5
.
Seco
nd e
xp
e
rim
ent sev
erit
y ra
nge
with
Alie
nV
a
ul
t
Script ID
Vu
ln
I
D
Vu
ln
erability
CVSS
Sev
erity
1
0
3
6
7
4
V1
.B1
OS end
of
lif
e detectio
n
10
Seriou
s
1
0
0
0
7
2
V1
.B2
Ch
eck if
M
ailserv
e
r
an
swer
to VRFY
an
d
E
XPN
requ
est
5
Hig
h
9
0
1
2
0
2
V1
.B3
Ch
eck f
o
r
rlog
in
s
ervice
7
.5
Hig
h
1
0
0
0
8
0
V1
.B4
Ch
eck f
o
r
rsh
service
7
.5
Hig
h
8
0
2
2
3
6
V1
.B5
Fin
g
er
serv
ice
re
m
o
te inf
o
r
m
atio
n
dis
clo
su
re
v
u
ln
erability
5
Hig
h
1
0
5
0
4
2
V1
.B6
SSL/T
LS:
Op
en
SS
L
CC
S
m
an
in th
e
m
id
d
le
secu
rit
y
by
p
ass
vu
ln
erability
6
,8
Hig
h
1
0
3
9
3
6
V1
.B7
SSL/T
LS:
Op
en
SS
L
T
LS
‘heartbeat’
ex
ten
sio
n
in
f
o
r
m
at
io
n
dis
clo
su
re
v
u
ln
erability
5
Hig
h
8
0
0
9
1
V1
.B8
TCP ti
m
esta
m
p
s
2
,6
Mediu
m
Figure
3
.
V
uln
i
x
vu
l
ner
a
bili
ty
w
it
h Ali
enV
a
ul
t
3.
3
.
W
alkthr
ough an
aly
sis
w
ith V
uln
OS
Table
6
sho
w
s
the
walkt
hro
ugh
a
naly
sis
i
n
eac
h
phases
to
ide
ntify
the
threat
at
ta
ck
or
the
ex
plo
it
scor
e
t
o
be
us
e
d
in
the
m
ulti
plica
ti
on
with
the
vulne
ra
bili
t
y
scor
e
nam
ely
CVSS
in
T
a
ble
7
that
pr
es
ent
th
e
risk
val
ue
obta
ined.
An
e
xam
ple o
f
the
V1.
A1
vu
l
ner
a
bili
ty
is d
ru
pal cor
e crit
ic
al
r
e
m
ot
e cod
e exec
uti
on
with
a
value
of
7.5.
The
n
it
will
be
m
ulti
plied
by
the
possibil
it
y
of
the
th
reat
is
T1.1,
nam
ely
gen
eral
en
um
erati
on
is
10
,
T1
.
2
is
r
esearch
e
xp
l
oit
is
5,
T1.
5
is
S
QLMap
is
8
,
a
nd
T
1.12
is
we
b
en
um
erati
on
is
4.
The
risk
value
will
then
be
use
d
as
a
grap
h
s
o
that
It
is
eas
y
to
see
wh
ic
h
ty
pes
of
e
xp
l
oi
ts
and
vulne
ra
bili
ti
es
are
co
m
m
on
.
Penetrati
on
or
te
sti
ng
is
the
a
rt
or
m
easur
e
o
f
un
c
overi
ng
ri
sk
s
an
d
vulne
r
abili
ti
es
and
dig
gi
ng
deep
to
detect
how
m
uch
a
tar
get
can
c
om
pr
om
ise
in
any
kind
of
le
gitim
at
e
at
ta
ck.
It
also
trie
s
to
fin
d
add
it
ion
al
sec
ur
it
y
risks
t
hat
oft
en
do
n'
t
sh
ow
up
i
n
vu
l
ner
a
bili
ty
scans.
P
enetrati
on
te
sti
ng
will
i
nvolve
exp
l
oiti
ng
s
erv
e
rs
,
netw
orks,
fi
re
wall
s,
com
pu
te
rs,
to
fi
nd
vu
l
ner
a
bili
ti
es
,
and
draw
at
te
ntion
to
pr
act
ic
al
threats
involv
ed
wit
h
the
identifie
d
vu
l
ner
a
bili
ti
es.
Ap
a
rt
from
the
def
in
ed
pur
pose,
the
pe
netr
at
ion
te
st
appr
oach
ca
n
al
so
be
us
e
d
to
eval
uate
an
d
m
easur
e
the
s
us
pici
ou
s
po
w
er
m
echan
ism
of
t
he
syst
em
on
ho
w
capa
bl
e
or
str
ong
the
syst
e
m
Evaluation Warning : The document was created with Spire.PDF for Python.
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci
IS
S
N:
25
02
-
4752
Vuln
er
abil
it
y and ri
sk
as
sess
men
t f
or
opera
ti
ng
s
yst
e
m
(
O
S)
wi
th fram
ew
or
k
…
(
Adity
as
Wi
dja
jart
o
)
1649
is
in
pr
otect
in
g
against
va
rio
us
ty
pes
of
une
xpect
ed
m
al
iciou
s
at
ta
cks.
I
n
this
case,
the
T
able
8
sho
ws
the
risk
analy
sis o
f Vu
l
nOS
by u
si
ng
STRIDE
fr
am
e
work
to
un
der
s
ta
nd
t
he
cat
e
gorizat
ion
of the
thr
eat
s.
Table
6
.
V
ulnOS
walkt
hro
ugh
Threat
ID
Attack
T
h
re
at
W
alk
th
rou
g
h
Exp
lo
it Score
1
2
3
4
5
6
7
8
9
10
T1.1
Gen
eral
en
u
m
e
rati
o
n
V
V
V
V
V
V
V
V
V
V
10
T1.2
Exp
lo
it r
esearch
V
-
-
V
-
V
V
-
-
V
5
T1.3
SMB/R
PC en
u
m
e
r
atio
n
V
V
V
V
V
V
V
V
-
V
9
T1.4
Ad
m
in
acc
ess
V
-
-
-
-
-
-
-
-
-
1
T1.5
SQLM
ap
V
V
V
V
V
V
-
-
V
8
T1.6
Pass
wo
rd cra
ck
in
g
V
V
-
V
V
V
V
-
-
V
7
T1.7
SSH
V
V
V
V
V
V
V
V
V
-
9
T1.8
TT
Y
Shell
V
-
-
-
V
-
-
-
-
-
2
T1.9
Execu
tio
n
By
p
ass
-
V
-
-
-
-
-
-
-
-
1
T1.1
0
Co
m
p
ilin
g
E
x
p
lo
its
-
V
-
-
V
-
-
-
-
V
3
T1.1
1
Ch
m
o
d
-
-
V
-
-
-
-
-
-
-
1
T1.1
2
W
eb
enu
m
e
ration
-
-
-
V
-
V
-
V
V
-
4
T1.1
3
Tr
an
sf
er
f
ile
-
-
-
-
V
V
-
-
-
V
3
T1.1
4
Po
p
3
-
-
-
-
-
-
V
-
-
-
1
T1.1
5
Fin
g
erprint
in
g
-
-
-
-
-
-
-
V
-
-
1
Table
7
.
V
ulnOS esti
m
at
ion
r
isk a
naly
sis
Vu
ln
I
D
CVSS
Threat
ID
Sco
re
Exp
lo
it
Ris
k
I
D
Ris
k
V1
.A1
7
,5
T1.1
10
R1
.A1
75
T1.2
5
R1
.A2
3
7
,5
T1.5
8
R1
.A3
60
T1.1
2
4
R1
.A4
30
V1
.A2
4
,3
T1.7
9
R1
.A5
3
T1.6
9
R1
.A6
3
8
,7
T1.1
1
1
R1
.A7
4
,3
V1
.A.
3
2
,6
T1.1
0
3
R1
.A8
7
,8
T1.7
9
R1
.A9
2
3
,4
V1
.A4
2
,6
T1.1
2
4
R1
.A10
1
0
,4
Table
8
.
Ri
s
k
a
naly
sis o
f Vu
l
nOS
with
STRI
DE
Ris
k
I
D
STRID
E
Sp
o
o
f
i
n
g
Ta
m
p
e
ring
Rep
u
d
iatio
n
Inf
o
r
m
atio
n
Dis
clo
su
re
Den
ial of
Ser
v
ice
Elevatio
n
of
Pr
iv
ilag
e
R1
.A1
-
-
-
V
-
-
R1
.A2
-
-
-
V
-
-
R1
.A3
-
-
V
-
-
-
R1
.A4
-
-
-
-
V
-
R1
.A5
-
-
-
-
-
V
R1
.A6
-
-
-
-
-
V
R1
.A7
-
-
-
-
-
V
R1
.A8
-
-
-
-
V
-
R1
.A9
-
-
-
-
-
V
R1
.A10
-
-
V
-
-
-
3.
4
.
W
alk
th
r
ough
a
n
aly
sis
w
ith V
ulni
x
Si
m
il
ar
li
ke
pr
evio
us
a
naly
sis,
T
able
9
sho
w
s
the
ex
plo
it
sc
or
e
wh
il
e
T
a
ble
10
s
how
s
the
risk
value
ob
ta
ine
d
by
m
ul
ti
plyi
ng
th
e
vulne
rab
il
it
y
sco
re
C
VS
S
an
d
the
ex
pl
oit
sco
re.
For
exam
ple,
the
V
1.
B1
vu
l
ner
a
bili
ty
is
OS
end
o
f
li
fe
detect
ion
with
a
value
of
10. Th
e
n
it
will
be
m
ulti
plied
by
the
po
s
sible
thr
eat
i
s
T2.1,
nam
el
y
Netdisc
ov
e
r
is
3
an
d
T2.3
is
ARP
scan
ning
is
1.
The
risk
va
lue
will
then
be
us
e
d
as
a
graph
f
or
easy
viewin
g,
wh
ic
h
ty
pes
of
exp
loit
at
ion
a
nd
vu
l
ner
a
bili
ty
occu
r
f
reque
ntly
.
The
assu
r
an
ce
of
an
IT
pro
du
ct
m
eans
that
the
pro
du
ct
m
eet
s
it
s
secur
it
y
ob
j
ect
ives,
t
hat
the
sec
ur
it
y
m
e
asur
e
s
im
ple
mented
by
the
pro
duct
will
be
a
ble
to
co
un
te
r
the
t
hr
eat
as
it
occ
ur
s
[
26
]
-
[
28
]
.
The
fr
e
quency
of
pe
netrati
on
te
sti
ng
respo
nds
t
o
m
any
factor
s,
f
ro
m
i
nd
us
try
ty
pe
to
netw
ork
te
chn
ol
og
y
an
d
regulat
ory
com
pliance.
If
there
is
so
m
e
kin
d
of
industry com
pliance regulat
io
n,
the
n
pe
netra
ti
on
test
ing
s
hould
also
be
r
un as essen
ti
al
to
m
eet
tho
se n
eeds.
I
t
is
of
te
n
rec
omm
end
ed
t
hat
pe
netrati
on
te
sts
be
sch
ed
uled
if
any
of
the
f
ollow
i
ng
occ
urs,
su
c
h
as
si
gnific
an
t
Evaluation Warning : The document was created with Spire.PDF for Python.
IS
S
N
:
2502
-
4752
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci,
Vo
l.
23
, N
o.
3
,
Se
ptem
ber
20
21
:
1643
-
16
53
1650
disruptio
n
to
the
netw
ork
or
infr
a
struct
ur
e
,
increase
d
m
edi
a
awar
e
ness
a
nd
at
te
ntio
n
th
at
cou
ld
inc
rea
se
the
li
kelihood
of
an
at
ta
ck,
ad
di
ng
offices
or
cha
ng
i
ng
offi
ce
locat
ions
to
the
net
work,
the
la
te
s
t
in
du
st
ry
regulat
ion
s
require
ad
diti
onal
com
pliance,
pa
tc
hes
secu
rity
functi
ons,
an
d
new
a
pp
li
cat
ion
s
or
i
nfrastr
uctu
re
are
ad
de
d
to
th
e
app
li
cat
io
n
s
yst
e
m
.
In
te
resti
ng
ly
,
the
m
os
t
com
m
on
factor
s
ca
n
be
at
tribu
te
d
to
the
la
ck
of
consi
ste
nt
proc
edures
for
a
naly
sing
a
nd
colle
ct
ing
data
er
rors
ge
ne
rated
duri
ng
softwa
re
dev
el
op
m
ent,
wh
ic
h
is
extrem
el
y
diff
ic
ult
a
nd
ti
m
e
-
co
nsum
ing
[
29
]
,
[
30
]
.
O
ne
so
luti
on p
r
ovid
ed
for
c
om
plexity
is
through
the u
se
of n
et
work kn
owle
dge s
of
t
ware SD
N
e
xisti
ng
so
l
ution
s
, only
the l
ogic
of n
e
twork
d
e
vices
[31
]
-
[
33]
.
Table
9
.
V
uln
i
x walkth
r
ough
Threat
ID
Attack
T
h
re
at
W
alk
th
rou
g
h
Exp
lo
it Score
1
2
3
4
5
6
7
8
9
10
T2.1
Netwo
rk d
isco
v
ery
V
-
V
-
-
-
V
-
-
-
3
T2.2
Po
rt
scan
n
in
g
V
V
V
V
V
V
-
V
V
V
9
T2.3
ARP scan
n
in
g
-
-
-
-
-
-
-
V
-
-
1
T2.4
Fin
g
er
scan
n
in
g
V
-
V
-
V
-
V
-
V
V
6
T2.5
NFS enu
m
e
ration
V
V
V
V
V
V
V
V
V
V
10
T2.6
SSH E
n
u
m
e
ration
V
V
-
-
V
-
-
-
-
-
3
T2.7
Users enu
m
e
ration
-
V
V
-
V
-
V
-
V
V
6
T2.8
Netcat
-
-
V
-
-
-
-
-
-
-
1
T2.9
SMT
P
E
n
u
m
e
ratio
n
-
-
V
-
V
-
-
-
V
V
4
T2.1
0
Bru
tef
o
rce
V
V
V
-
V
-
-
-
-
-
6
T2.1
1
Edit /etc/p
ass
wd
-
V
-
-
-
-
-
-
-
-
1
T2.1
2
Ad
d
ed
a
n
ew us
er
with
sp
ecif
ied
I
D t
o
had
access
-
V
V
V
V
V
-
V
V
-
7
T2.1
3
Created .ssh
in th
e
re
m
o
te ho
m
e dire
c
to
ry
-
V
V
V
V
V
V
V
V
V
9
T2.1
4
Su
d
o
-
l sh
o
ws th
at vu
ln
ix
allowed
to
ed
it
/etc/ex
p
o
rts f
ile
V
V
V
V
V
V
V
V
V
V
10
T2.1
5
Disab
le r
o
o
tsq
u
ashing
-
V
V
-
-
V
V
V
V
-
6
T2.1
6
User re
m
o
te
acc
es
V
-
V
V
V
-
V
V
V
V
9
T2.1
7
Re
m
o
te w
rite
a
cce
ss
-
V
V
V
-
V
-
-
V
V
6
T2.1
8
Co
p
y
/b
in
/b
ash
to th
e r
e
m
o
te
r
o
o
t dire
cto
ry
V
-
-
-
-
-
-
-
-
-
1
T2.1
9
Ro
o
t acce
ss
V
V
V
V
-
V
V
V
V
V
9
T2.2
1
Sy
ste
m
r
eb
o
o
t r
eq
u
ired
V
V
V
V
-
V
V
V
-
-
7
T2.2
2
./bas
h
-
p
-
-
-
-
-
-
V
-
-
-
1
T2.1
Netwo
rk d
isco
v
ery
V
-
V
-
-
-
V
-
-
-
3
Table
10
.
Vu
l
ni
x
est
im
a
ti
on
r
i
sk
a
naly
sis
Vu
ln
I
D
CVSS
Threat
ID
Sco
re
Exp
lo
it
Ris
k
I
D
Ris
k
V1
.B1
10
T2.1
3
R1
.B1
30
T2.3
1
R1
.B2
10
V1
.B2
5
T2.9
4
R1
.B3
20
V1
.B3
7
,5
T2.2
9
R1
.B4
6
7
,5
V1
.B4
7
,5
T2.5
10
R1
.B5
75
T2.6
3
R1
.B6
2
2
,5
V1
.B5
5
T2.4
6
R1
.B7
30
V1
.B6
6
,8
T2.1
9
9
R1
.B8
6
1
,2
T2.6
3
R1
.B9
2
0
,4
T2.8
1
R1
.B1
0
6
,8
V1
.B7
5
T2.2
0
10
R1
.B1
1
50
V1
.B8
2
,6
T2.1
3
R1
.B1
2
7
,8
Af
te
r
e
ve
ry pr
ocess was
done
, th
e ris
k
a
naly
sis was con
duct
ed
li
ke
be
f
ore by cete
gorizi
ng
t
he
th
reats
as
can
be
see
n
i
n
T
a
ble
11.
Use
r
e
ducat
ion
is
ce
ntral
t
o
im
ple
m
enting
a
cy
be
rsecurit
y
po
li
cy
,
wi
th
key
el
e
m
ents
in
a
reali
sti
c
con
t
ext
of
sim
ulatio
n
relat
ed
to
the
dy
nam
ics
of
a
cy
be
r
at
ta
ck,
the
on
go
i
ng
dev
el
op
m
ent
of
the
inf
rastr
uc
ture,
existi
ng
vulne
rab
il
it
ie
s
and
the
nee
d
t
o
be
a
war
e
of
th
ei
r
pote
ntial
im
pact
[34
]
,
[
35]
.
The
m
ai
n
functi
on
of
a
n
ideal
network
m
anag
em
ent
syst
e
m
is
to
i
m
pr
ove
th
e
op
e
rati
onal
capaci
t
y
of
the
netw
ork
by
m
a
intai
nin
g
the
be
st
pe
rfor
m
ance
of
the
networ
k
op
e
rati
on,
w
hi
ch
co
uld
be
thr
ough
pr
e
dicti
ng
th
e
resu
lt
base
d
on
po
sit
ive
an
d
ne
gative
ind
ic
at
or
s
a
nd
a
dv
a
nc
ed
plan
ning
[
36
]
,
[
37]
.
The
re
fore,
orga
nizat
ion
s
m
us
t
m
ee
t
the
necessa
ry
an
d
s
pecific
ri
gorous
requirem
ents
to
ac
hie
ve
the
sa
fety
-
sta
bili
ty
bounda
ry
in
th
e
pr
e
ven
ti
on
of
w
or
st
-
case
sc
enar
i
os
[
38
]
.
C
on
si
der
i
ng
t
hat
the
com
plexity
and
hete
roge
neity
of
netw
orks
bu
il
t i
n
a co
m
pan
y'
s sp
eci
fic env
iro
nm
ent h
ave si
m
ultaneou
sly
r
ed
uced
the e
f
fici
ency of
networ
k
adm
inist
rator
s
[39],
vul
ner
a
bili
ti
es
assess
m
e
nt
an
d
a
naly
sis
regularly
can
su
pp
or
t
t
he
em
plo
ye
es
in
gi
vin
g
t
he
confide
nce in
o
r
der
to pre
pare t
he
m
sel
ves
t
hro
ugh
trai
ning and und
e
rsta
nd
i
ng
fo
r
pro
pe
r
con
t
ro
l an
d handli
ng
Evaluation Warning : The document was created with Spire.PDF for Python.
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci
IS
S
N:
25
02
-
4752
Vuln
er
abil
it
y and ri
sk
as
sess
men
t f
or
opera
ti
ng
s
yst
e
m
(
O
S)
wi
th fram
ew
or
k
…
(
Adity
as
Wi
dja
jart
o
)
1
651
act
ivit
y.
It
is
doubtf
ul
that
s
om
e
m
od
el
ing
an
d
a
naly
sis
cou
l
d
acc
ur
at
e
ly
and
cl
early
pr
e
dict
ho
w
s
uch
an
at
ta
ck
would
occur
on
the
netw
ork
in
fr
as
tructu
re,
re
su
lt
ing
in
a
s
hu
t
dow
n
or
dis
rup
ti
on
,
f
ollo
wed
by
a
colli
sion
as
th
e
co
ns
eq
ue
nce
s
[
40
]
,
[
41]
.
B
ut
at
the
ver
y
le
ast
,
it
can
pr
esents
a
dep
ic
t
ion
a
nd
al
te
rnat
ive
so
luti
on
f
or
pr
edict
ion
a
nd
prepa
rati
on
f
or
the
orga
nizat
io
n.
I
n
gener
al
,
awar
e
ness
a
nd
pr
e
par
at
io
n
for
asset
su
sta
ina
bili
ty
and
perform
ance
of
te
n
bec
om
e
the
ta
rg
et
at
ta
ck
throu
gh
creati
ng
fail
ures
in
the
pr
oc
ess
of
secur
i
ng
the
as
set
s.
T
hu
s
,
it
s
hould
be
no
te
d
that
in
fr
a
struc
ture
is
ext
rem
e
il
y
crit
ic
al
in
orde
r
t
o
pro
vid
e
t
he
increase
d
le
ve
l
of
co
nvenie
nce
of
co
nnec
ti
vity
by
decre
asi
ng
the
su
s
cepti
bili
ty
to
cy
ber
at
ta
ck
t
hro
ugh
routine a
nd r
e
gula
r v
uln
era
bili
ty
assessm
ent [
42
]
,
[43
]
.
Table
11
.
Ri
sk
analy
sis o
f Vu
l
nix
with
STRI
DE
Ris
k
I
D
STRID
E
Sp
o
o
f
i
n
g
Ta
m
p
e
ring
Rep
u
d
iatio
n
Inf
o
r
m
atio
n
Dis
clo
su
re
Den
ial of
Ser
v
ice
Elevatio
n
of
Pr
iv
ilag
e
R1
.B1
-
-
-
V
-
-
R1
.B2
-
-
-
-
V
-
R1
.B3
-
-
-
V
-
-
R1
.B4
-
-
-
-
V
-
R1
.B5
-
-
-
V
-
-
R1
.B6
-
-
-
-
-
V
R1
.B7
-
-
-
-
V
-
R1
.B8
-
-
-
-
-
V
R1
.B9
-
-
-
-
-
V
R1
.B1
0
-
V
-
-
-
-
R1
.B1
1
-
-
-
-
-
V
R1
.B1
2
-
-
-
V
-
-
4.
CONCL
US
I
O
N
In
this
stu
dy,
there
are
se
ver
a
l
lim
i
ta
ti
on
s
an
d
dr
a
w
backs
w
hich
can
be
use
d
as
a
ref
ere
nc
e
and
al
so
a
co
ns
ide
rati
on
for
furthe
r
researc
h.
It
c
an
al
s
o
assist
orga
nizat
ions
with
t
heir
c
on
si
der
at
io
ns
befor
e
i
m
ple
m
enting
the
Alie
nV
a
ult
so
ftwa
re
in
the
V
uln
e
ra
bili
ty
a
ssess
m
ent.
The
sugg
e
sti
on
s
ge
ner
at
ed
in
this
stud
y
a
re
is
be
ing
a
s
:
the
us
e
of
la
r
ge
resou
rces
in
the
a
pp
li
cat
ion
of
the
Alie
nV
a
ult
s
oft
war
e,
so
that
i
t
al
so
requires
la
rg
e
r
eso
ur
ces f
or
t
he
ser
ver
u
se
d.
By
hav
in
g
V
A,
of
co
urse o
ne
way
to quickly
r
es
pond
in gu
ard
i
ng
the
IT
a
ssets
to
s
us
ta
in
the
business
pro
ces
s
an
d
aw
are
ne
ss
over
secu
rity
vu
l
ner
a
bili
ties
in
the
e
nvir
on
m
ent,
wh
ic
h
in
t
he
f
ur
t
her
,
sup
port
the
decisi
on
m
aking
t
o
m
i
tig
at
e
the
po
te
ntial
threats
thr
ough
qu
a
ntific
at
ion
of
the
risk
as
the
r
eg
ular
vi
rtual
su
pp
or
t.
Co
ns
i
der
at
io
n
is
nee
ded
in
c
hoos
i
ng
open
s
ource
secur
it
y
inf
orm
at
ion
and
e
ve
nt
m
an
agem
ent
(
SI
E
M
)
software
usi
ng
cl
oud
ser
vices
so
t
hat
la
rg
e
resou
rce
re
qu
i
rem
ents
fo
r
serv
e
r
s
are
no
t
nee
ded
so
t
hat the
data
obtai
ned is m
or
e c
om
plete
and
easy
t
o
a
naly
ze.
REFERE
NCE
S
[1]
D.
Natha
ns,
“
Designing
and
Bu
il
ding
a
Se
cur
ity
Opera
ti
ons
Ce
nte
r,”
Britis
h
Libr
ary
Catal
oguing
-
in
-
Publ
i
catio
n
Data,
Syngr
ess
,
2015,
pp
.
1
-
9
,
d
oi:
10
.
1016/C20
13
-
0
-
19158
-
1.
[2]
G.
Sadows
ky
,
J.
X.
Dem
pse
y
,
A.
Gree
nber
g
,
B.
J.
Ma
ck,
and
A.
Schwart
z,
“
Information
Tec
hnology
Se
curity
Handbook
,
”
Inter
nati
onal Bank
f
or R
ec
onstrcu
ti
o
n
and
De
v.
/The
World
Bank
,
200
3.
[3]
S.
Jetty
,
“
Netwo
rk
Scanni
ng
Co
okbook
Prac
tica
l
Network
Secur
ity
using
Nm
ap
and
Ness
us
7,
”
Pac
k
t
Publishin
g
Ltd
,
pp.
10
-
11,
2
018.
[4]
D.
Beke
r
and
S.
Yerus,
“
The
Stat
e
of
V
ulne
rab
il
i
ti
es
2
019,
”
Jul
y
20
20.
[Online
]
.
Avail
ab
le
:
fro
m
:
htt
ps://
ww
w.i
m
per
va.com/blog/
th
e
-
state
-
of
-
vuln
er
abi
litie
s
-
in
-
2019
/.
[5]
M.
Abom
har
a
a
nd
G.
M.
Køien
,
“
C
y
ber
Secur
ity
and
the
Inte
rn
et
of
Th
ings:
Vuln
era
bi
li
t
ie
s,
Threa
ts,
Intrud
ers,
and
Atta
cks,
”
Journal
of
Cybe
r
Sec
u
rity
and
Mob
il
i
t
y
,
vo
l. 4, pp. 65
-
88,
2015
,
doi
:
10
.
13052/jcsm
2245
-
1439.
414.
[6]
J.
S.
Ti
l
le
r
,
“
CISO
’s
Guide
to
Penet
r
at
ion
Te
st
in
g:
A
Fram
ework
to
Plan,
Mana
g
e
and
Maximi
ze
Bene
fi
ts,”
C
RC
Pr
ess Tayl
or
&
Franci
s Gr
oup
,
2012,
doi
:
10
.
12
01/b11306.
[7]
R.
Khan,
K.
Mc
La
ughli
n
,
D.
Lavert
y
,
and
S.
Se
ze
r,
"S
TRIDE
-
b
ase
d
thr
ea
t
m
odel
ing
for
c
y
b
er
-
ph
y
sic
al
s
y
stems
,
"
2017
IEE
E
PES
Innov
ative
S
mar
t
Gr
id
Technol
ogie
s
Confe
r
enc
e
Europe
(
ISGT
-
Europe)
,
2
017,
pp.
1
-
6
,
d
oi:
10.
1109/ISGTE
urope
.
2017.
8260
283.
[8]
D.
R.
Mi
ll
er
,
S.
Harri
s,
A
.
A.
H
arp
er,
S.
VanD
yke,
and
C
.
Bl
ask,
“
Secur
ity
Inf
orm
at
ion
and
E
vent
Man
age
m
e
nt
(SIEM) Implementation,”
The
M
cGraw
-
Hill
Com
panie
s
,
2011
.
[9]
J.
Reuvi
d
,
“
Man
agi
ng
C
y
b
erse
cu
rity
Risk:
Cases
Studie
s a
nd
Solu
ti
ons,”
Legends T
eam
Gr
oup
,
20
18.
[10]
A.
Kathe
r
ine,
J.
Seale,
T.
Mc
donal
d,
H
.
Pard
ue,
W
.
Gl
isson,
and
M.
Ja
cobs,
“
MedDevRisk:
Risk
Anal
y
s
is
Methodol
og
y
fo
r
Networke
d
M
edi
c
al
Dev
ices,”
in
Pro
ce
ed
ings
of
th
e
51st
Hawaii
Int
ernati
on
al
Confe
ren
ce
o
n
Syste
m Scien
ce
s
,
2018,
doi: 10.
24
251/HICSS
.
2018.
414.
Evaluation Warning : The document was created with Spire.PDF for Python.
IS
S
N
:
2502
-
4752
Ind
on
esi
a
n
J
E
le
c Eng &
Co
m
p
Sci,
Vo
l.
23
, N
o.
3
,
Se
ptem
ber
20
21
:
1643
-
16
53
1652
[11]
S.
Schina
g
l,
K
.
Schoon,
and
R.
Paans,
"A
Fram
ework
for
Desig
ning
a
Se
cur
i
t
y
Opera
ti
ons
C
entre
(SO
C),
"
2015
48th
Hawaii
Inter
nati
onal
Conf
ere
nce on
S
yste
m
Sci
en
ce
s
,
2015,
pp.
2253
-
2262
,
doi:
10
.
1109/HI
C
SS
.
2015.
270.
[12]
A.
Micha
il,
“
Secur
ity
Oper
at
ion
Cent
ers
a
Business
Perspec
ti
ve,”
Utrec
ht
Unive
rs
it
y
MSc
in
Busin
ess
Informatic
s
,
2015.
[13]
E.
Conr
ad, S.
Mi
sena
r
and
J.
Feld
m
an,
“
CISS
P St
ud
y
Guide,”
N
e
wnes
,
2012
,
doi
: 10.1016/
C2011
-
0
-
07337
-
4.
[14]
J.
Fruhlinge
r,
“
Thre
a
t
Modell
in
g
Expl
ai
n
ed:
A
Proce
ss
for
Ant
ic
ip
at
ing
C
y
ber
Atta
cks,
”
IDG
Comm
unit
y,
Inc
,
2020.
[Online
]
.
Avail
able:
https
:/
/www
.
c
soonl
ine
.
com/ar
ticl
e/
3
537370/t
hre
at
-
m
odel
ing
-
expl
a
ined
-
a
-
proc
ess
-
for
-
ant
i
ci
pa
ti
ng
-
c
y
b
er
-
attac
ks
.
html
.
[
Ret
ri
eve
d
at Decem
ber
2021]
.
[15]
I.
Kam
il,
M.
L.
Julham,
and
A
.
R.
Lub
is
,
“
Mana
gement
Mai
nte
nan
ce
S
y
ste
m
for
Remote
Control
b
ase
d
o
n
Microc
ontro
ll
er
and
Virtua
l
Priv
at
e
Serve
r
,
”
Ind
onesian
Journal
of
El
ectric
al
En
gine
ering
and
C
omputer
Sci
ence
(
IJE
ECS)
,
vol. 1
6,
no
.
3
,
pp
.
134
9
-
1355,
2019
,
d
oi:
10
.
11591/ije
e
cs.
v16.
i3
.
pp134
9
-
13
55.
[16]
R.
Fauz
i,
M
.
H
ari
ad
i,
S.
M.
S.
Nugroho,
and
M.
Lubi
s.
“
Defe
nse
Beh
avi
or
of
Real
T
ime
Strat
eg
y
G
ames:
Com
par
ison
bet
wee
n
HF
SM
an
d
FS
M,”
Indone
sian
Journal
o
f
El
e
ct
ri
cal
Eng
ine
ering
and
C
omputer
Sci
en
c
e
(
IJE
ECS)
,
vol. 1
3,
no
.
2
,
pp
.
634
-
642,
Febru
aa
r
y
20
19,
doi
:
10
.
11
591/i
jeec
s.v13
.
i
2.
pp634
-
642.
[17]
H.
A.
A.
Julham,
A.
R.
Lubi
s,
a
nd
M.
Lubi
s,
“
Deve
lopment
of
S
oil
Moisture
Me
asure
m
ent
with
W
ire
le
ss
Sensor
W
eb
-
Based
Conce
pt
,
”
Indon
esia
n
Journal
of
El
e
ct
rical
Engi
n
ee
r
ing
and
Comput
er
Sci
en
ce
(
IJEE
CS)
,
vol.
13,
n
o
.
2,
pp
.
514
-
520
,
Februa
r
y
2019
,
doi:
10
.
11591/ij
ee
cs.
v13
.
i2
.
pp51
4
-
520.
[18]
A.
Alm
aa
rif
and
M.
Lubi
s.
“
Vulner
ability
As
sess
m
ent
and
Penetrat
ion
Te
sting
(
VA
PT)
Fram
ew
ork:
Case
Stud
y
of
Governm
ent
’s
W
ebsit
e,
”
Int
ernati
onal
J.
on
Ad
vanc
e
Sc
.
Eng.
And
Inf.
Tech
,
v
ol.
10,
no.
5,
pp.
1874
-
1880,
2020,
doi:
10
.
18517/ij
ase
it.10.
5
.
8862.
[19]
M.
Abdurohm
an
and
B
.
S.
Nugroho,
“
Te
c
hnic
a
l
Spec
ifi
c
at
ion
for
Eff
ective
N
ext
Gen
era
t
ion
Netwo
r
k
Inte
rco
nn
ec
t
ion
in
Indone
sia,”
I
nte
rnational
J.
o
n
Adv
ance
S
c.
E
ng.
And
Inf.
Te
c
h.
vol.
10
,
no
.
3
,
pp.
1153
-
1162,
2020,
doi
:
10
.
18
517/i
ja
se
it.10.
3
.
5753.
[20]
B.
Murugana
nt
ham,
P.
Sham
il
i,
S.
G
.
Kum
ar,
and
A.
Murugan,
“
Quant
um
Cry
p
togra
p
h
y
for
Se
cur
e
d
Com
m
unic
at
ion
Network,
”
Inte
r
nati
onal
Journal
of
El
ec
tri
cal
&
Computer
Engi
nee
ring
(
IJE
CE)
,
vol.
10,
no.
1,
pp.
407
-
414
,
20
20,
doi
:
10
.
1159
1/i
jece
.
v10i1
.
pp
407
-
414.
[21]
D.
Mous
saoui,
M.
Feham,
B
.
A.
Bensab
er,
an
d
B.
K
adr
i,
“
Secur
ing
Veh
ic
ul
a
r
Cloud
Ne
tworks,”
Int
ernati
on
a
l
Journal
of
Elec
tri
cal
&
Co
mputer
Engi
ne
ering
(
IJE
CE)
,
vol.
9,
no.
5,
pp.
4154
-
4
162,
201
9,
do
i:
10.
11591/ijece.
v
9i5.
pp4154
-
416
2.
[22]
M.
Lubi
s,
R.
Fauzi
,
A.
R.
Lubi
s
,
and
R.
Fauzi
,
“
A
Case
Study
of
Univer
siti
es
Dorm
it
or
y
Reside
n
ce
Mana
gemen
t
S
y
stem
(DRMS)
in
Indon
esia
,
”
in
IE
EE
Int.
Con
f.
Cybe
r
an
d
IT
Serv
ic
e
,
2018,
doi
:
10.
1109/CIT
SM
.
2018.
8674313
.
[23]
R.
Johari,
I.
Ka
ur,
R.
Tri
pa
thi,
and
K.
Gupta,
"P
ene
tra
ti
on
T
esti
ng
in
IoT
Network,
"
2020
5th
Inte
rnationa
l
Confe
renc
e
o
n
Computing,
Comm
unic
ati
on
and
Se
curit
y
(
ICCCS)
,
2020,
pp.
1
-
7,
doi
:
10.
1109/ICCCS49678.2020.
927
6853.
[24]
S.
Karm
okar
,
M.
M.
Mohin
,
M.
K.
Islam,
M.
R
.
Alam,
and
M.
M.
R
a
hm
an,
“
Quanti
t
at
iv
e
Vulner
abil
ity
As
sessment:
An
Approac
h
to
R
e
duce
B
ia
ses
in
Disaster
Vulner
abi
lit
y
As
sess
me
nt,”
Curr
ent
W
orld
Envi
ronm
e
nt,
vol.
14
,
no
.
3
,
pp
.
383
-
399
,
2019
,
doi: 10.
5194
/i
sprs
-
arc
hive
s
-
XLII
-
4
-
703
-
2018.
[25]
L.
C
hang
,
G.
Chen,
S.
Cao
,
and
C.
Zhe
ng
,
“
Vulner
abi
lit
y
As
sessment
of
Regi
onal
W
a
te
r
Resourc
es,
”
I
OP
Confe
renc
e
Seri
es
Earth
and
Env
ironmenta
l
Sci
en
ce
vol.
50
8,
p.
012026,
April
2020,
doi:
10.
1088/1755
-
1315/508/
1/012
026.
[26]
A.
Bia
l
as,
“
Vulner
ab
il
i
t
y
As
se
ss
m
ent
of
Sens
or
S
y
stems
,
”
S
ensors
,
vol.
19,
no.
11,
pp.
2
518,
2019,
doi
:
10.
3390/s19112518.
[27]
K.
Maha
ja
n
and A.
M.
Kim
,
“Vu
lne
rab
il
i
t
y
As
sess
m
ent
of
Alber
ta
’s Provinc
ia
l
Highwa
y
Network,”
Tr
anspor
tat
ion
Re
search
In
te
rdi
scipl
inary
Pe
rs
p
ec
t
iv
es
,
vol
.
6
,
p
.
100171,
Jul
y
20
20,
doi
:
10
.
1016
/j
.
t
rip.
2020
.
1001
71.
[28]
C.
Sz
y
m
ula
a
nd
N.
Besinovi
c,
“
Pass
enge
r
-
ce
nt
ere
d
Vuln
era
bi
li
t
y
As
sess
m
ent
of
Rai
l
wa
y
Networks,
”
Tr
anspo
rtati
on
Re
search Part
B
Methodol
og
ic
a
l
,
vol
.
136
,
pp
.
30
-
61,
June
2020,
doi:
10
.
1016/j.tr
b.
2020.
03
.
008.
[29]
R.
Adebi
a
y
e
,
“
Miti
gating
Vuln
era
bi
li
t
y
Risk
in
C
y
ber
se
cur
i
t
y
us
ing
Predi
ct
iv
e
M
ea
sures,
”
Int
ernati
onal
Journal
of
Adv
anc
ed
S
ci
e
nti
fic
Re
search
&
Dev
el
op
ment
,
vo
l.
4,
no.
10
,
pp
.
12
-
27,
Octo
ber
2017,
do
i:
10.
26836/ijasrd/
2017/v4/
i10/
410
6.
[30]
D.
Rogows
ki,
"S
oftwa
r
e
imple
m
ent
at
ion
of
co
m
m
on
cri
te
ria
re
la
t
ed
design
pa
tterns,"
2013
Fe
d
erate
d
Confe
r
en
ce
on
Computer
Sc
i
enc
e
and
In
formation
S
yste
ms
,
2
013,
pp
.
1147
-
1
152.
[31]
D.
Magin,
R
.
Khondoker,
and
K.
Ba
y
aro
u
,
“
Secur
ity
Ana
l
y
s
is
of
OpenRa
di
o
and
SoftRAN
with
STRIDE
Fram
ew
ork,
”
The
24th
int
ernational
conf
ere
n
ce
on
compute
r
communic
ati
ons
and
appli
cat
ion
s
(
ICCCN
2015
)
.
IEE
E
,
vo
l. 38, 2
015.
[32]
J.
Straub,
"M
odel
ing
Att
ac
k,
Defe
nse
and
T
hre
at
Tr
ee
s
and
the
C
y
be
r
Kill
Chai
n,
ATT&CK
and
STRID
E
Fram
eworks
as
Bla
ckbo
ard
A
rch
itect
ur
e
N
etw
orks,"
2020
IEE
E
In
te
rnatio
nal
Confe
ren
ce
on
Smar
t
Clo
ud
(
Sma
rtCloud)
,
2020,
pp
.
148
-
15
3,
doi
:
10
.
1109/
Sm
art
Cloud49737.
2020.
00035
.
[33]
M.
Bret
t
and
J.
Parke
r,
“
A
Fram
ework
to
Understa
nd
Lo
cal
Governm
ent
Ne
twork
Envi
ronm
ent
From
C
y
b
er
Secur
ity
P
erspe
c
ti
ve
.
D
eveloping
an
Open
Sourc
e
Too
l
Kit
for
L
oca
l
Governm
ent
,
”
Ex
p
loring
Cy
ber
Sec
uri
ty
i
n
Local
Gove
rnm
e
nt
,
Mar
ch
2019
,
doi:
10
.
6084/m9.fi
gshare
.
996372
2.
v1.
[34]
G.
Subaşu,
L.
R
oşu,
and
I.
B
ădo
i,
"M
odel
ing
an
d
sim
ula
ti
on
ar
c
hit
e
ct
ure
for
trai
ning
in
c
y
b
er
de
fen
ce
ed
uc
at
ion
,
"
2017
9th
Inte
rnational
Confe
r
e
nce
on
Elec
tron
ic
s,
Computers
and
Arti
ficial
In
te
lligen
ce
(
ECAI)
,
2017,
pp.
1
-
4,
doi:
10
.
1109/E
C
AI.2017.
816639
6.
Evaluation Warning : The document was created with Spire.PDF for Python.