ANALISIS FILE LOG APACHE SERVER TERHADAP DETEKSI SERANGAN DICTIONARY ATTACK PADA FORM LOGIN APLIKASI WEB

  • Muhammad Rafi Bayu Saputra Saputra
    Politeknik Negeri Samarinda
  • Rihartanto
    Politeknik Negeri Samarinda
  • Ansar Rizal
DOI: https://doi.org/10.23960/jitet.v14i3.10686
Keywords Brute Force, Apache, File Log, Keamanan Web, Burp Suite
Abstract Views (Last 12 Months)
4 Abstract Views
2 Downloads

Abstract

Keamanan aplikasi web menjadi salah satu aspek krusial dalam infrastruktur jaringan saat ini. Salah satu ancaman yang paling sering dieksploitasi adalah serangan brute force, khususnya menggunakan teknik dictionary attack pada halaman autentikasi. Penelitian ini bertujuan untuk menganalisis efektivitas pemantauan file log pada Apache Web Server dalam mendeteksi anomali serangan tersebut. Pengujian dilakukan secara lokal menggunakan Damn Vulnerable Web Application (DVWA) sebagai target dan Burp Suite sebagai alat simulasi serangan. Hasil penelitian menunjukkan bahwa serangan dictionary attack meninggalkan jejak digital yang masif pada access.log, berupa lonjakan permintaan metode POST dalam rentang waktu sepersekian detik. Kesimpulan dari penelitian ini menegaskan bahwa implementasi log monitoring merupakan langkah fundamental yang sangat efektif untuk deteksi dini dan investigasi forensik terhadap ancaman keamanan server.

Downloads

Download data is not yet available.

References

OWASP Foundation, "OWASP Top 10: 2021-Identification and Authentication Failures," Open Web Application Security Project, 2021.

M. H. Bhuyan, D. K. Bhattacharyya, and J. K. Kalita, "Network Anomaly Detection: Methods, Systems and Tools," IEEE Communications Surveys & Tutorials, vol. 16, no. 1, pp. 303-336, 2014.

S. A. Aljawarneh, M. B. Yassein, and M. A. Talafha, "A multithreaded brute force attack on web applications," in Proc. International Conference on Engineering & MIS (ICEMIS), Agadir, Morocco, 2016, pp. 1-5.

W. Stallings, Cryptography and Network Security: Principles and Practice, 8th ed. Pearson, 2020.

J. M. Kizza, Guide to Computer Network Security, 5th ed. Springer, 2020.

M. Roesch, "Snort: Lightweight Intrusion Detection for Networks," in Proc. 13th USENIX Conference on System Administration (LISA), Seattle, WA, 1999, pp. 229-238.

Apache Software Foundation, "Apache HTTP Server Version 2.4 Documentation - Log Files," 2023. [Online]. Available: https://httpd.apache.org/docs/2.4/logs.html.

R. A. R. Ashfaq, J. Z. Wang, C. Huang, H. Abbas, and Y. L. He, "Fuzziness based semi-supervised learning approach for intrusion detection system," Information Sciences, vol. 378, pp. 484-497, 2017.

A. Chuvakin, K. Schmidt, and C. Phillips, Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management. Elsevier, 2012.

S. S. C. Silva, R. M. P. Silva, R. C. G. Pinto, and S. N. Salles, "Botnet detection using log analysis," Computers & Security, vol. 31, no. 3, pp. 289-305, 2013.

B. B. Zarpelão, R. S. Miani, C. T. Kawakani, and S. C. de Alvarenga, "A survey of intrusion detection in Internet of Things," Journal of Network and Computer Applications, vol. 84, pp. 25-37, 2017.

K. Scarfone and P. Mell, "Guide to Intrusion Detection and Prevention Systems (IDPS)," NIST Special Publication 800-94, 2007.

D. Zuech, T. M. Khoshgoftaar, and R. Wald, "Intrusion detection and Big Heterogeneous Data: a Survey," Journal of Big Data, vol. 2, no. 3, 2015.

D. Duei Putri, G. F. Nama, and W. E. Sulistiono, “Analisis Sentimen Kinerja Dewan Perwakilan Rakyat (DPR) Pada Twitter Menggunakan Metode Naive Bayes Classifier,” JITET (Jurnal Informatika dan Teknik Elektro Terapan), vol. 10, no. 1, Jan. 2022.

A. R. Y. P. Dinata and I. Ahmad, "Penerapan Metode Klasifikasi Naive Bayes Terhadap Analisis Sentimen Ulasan Aplikasi MyOrbit," JITET (Jurnal Informatika dan Teknik Elektro Terapan), vol. 11, no. 3, pp. 586-591, 2023.

Cover
Published
2026-08-13
How to Cite
Saputra, M. R. B. S., Rihartanto, & Ansar Rizal. (2026). ANALISIS FILE LOG APACHE SERVER TERHADAP DETEKSI SERANGAN DICTIONARY ATTACK PADA FORM LOGIN APLIKASI WEB. Jurnal Informatika Dan Teknik Elektro Terapan, 14(3). https://doi.org/10.23960/jitet.v14i3.10686