Security Analysis and Threat Modeling of the Informatics Engineering Laboratory Information System (SILABTI) Using Attack Tree Methodology
DOI:
https://doi.org/10.56127/ijst.v5i2.2090Keywords:
Attack Tree, academic information system, cybersecurity, threat modeling, vulnerability assessmentAbstract
Academic information systems manage sensitive data whose integrity directly affects academic administration and student outcomes. Legacy intranet-based systems may remain vulnerable to both technical attacks and human-factor threats, particularly when outdated software, unencrypted communication, weak access controls, and privileged user access coexist within the same operational environment. Objective: This study aims to analyze the security vulnerabilities of the Informatics Engineering Laboratory Information System (SILABTI) and identify potential pathways for unauthorized modification of practicum grades and graduation statuses using a hierarchical Attack Tree approach. Methodology: This study employed an analytical systems-engineering design based on Attack Tree threat modeling. The assessment covered the SILABTI web application, local network environment, MySQL database architecture, and administrative workflows. System boundaries and technical conditions were identified through infrastructure assessment and network reconnaissance, followed by hierarchical decomposition of adversarial objectives into root goals, intermediate sub-goals, and technical execution leaf nodes using AND/OR relationships. The resulting attack pathways were qualitatively evaluated according to technical prerequisites, execution complexity, system exposure, and detection probability. Findings: The analysis identified four primary intrusion vectors: credential acquisition, application exploitation, database exploitation, and insider exploitation. Four pathways were considered particularly high-risk: local network sniffing, workstation keylogging, automated brute-force attacks, and insider bribery or coercion. These findings indicate that SILABTI's security risks arise from the interaction of legacy software, network communication weaknesses, endpoint privileges, authentication controls, and human factors. Implications: The findings support an eight-point defense-in-depth framework incorporating TLS/HTTPS, tamper-resistant audit logging, role-based access control, network access restrictions, stronger authentication controls, workstation privilege restriction, anti-spoofing measures, and institutional security governance. This framework can guide university IT administrators in strengthening legacy academic information systems. Originality: This study contributes a hierarchical threat-decomposition model specifically designed for a legacy intranet-based academic laboratory information system, integrating technical and human-layer attack pathways within a single security assessment framework.
References
Al-Shareeda, M. A., Manickam, S., & Sari, S. A. (2022). A Survey of SQL Injection Attacks, Their Methods, and Prevention Techniques. 2022 International Conference on Data Science and Intelligent Computing (ICDSIC),
Kasturi, S., Li, X., Li, P., & Pickard, J. (2024). A proposed approach to integrate application security vulnerability data with incidence response systems. American Journal of Networks and Communications, 13(1), 19-29. https://doi.org/10.11648/j.ajnc.20241301.12
Konarski, P., & Ptak, M. (2020). Method for attack tree data transformation and import into IT risk analysis expert systems. Applied Sciences, 10(23), 8423. https://doi.org/10.3390/app10238423
Li, M. (2023). An Effective Vulnerability Detection Framework for Web Applications Using Multi-Modal Data Representation. Computers & Security, 132, 103362. https://doi.org/10.1016/j.cose.2023.103362
National Institute of, S., & Technology. (2021). Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (NIST Special Publication 800-160 Volume 2 Revision 1, Issue. https://doi.org/10.6028/NIST.SP.800-160v2r1
National Institute of, S., & Technology. (2022). Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities (NIST Special Publication 800-218, Issue. https://doi.org/10.6028/NIST.SP.800-218
Oliveira, A. V. d. S. (2022). Web Application Security Testing and Assessment: A Systematic Literature Review. Journal of Systems and Software, 186, 111195. https://doi.org/10.1016/j.jss.2021.111195
Piètre-Cambacédès, L., & Bouillon, C. (2022). Boolean Logic Driven Attack Trees (BDAT): A Tree-Based Formalism for Cyber-Security Analysis. Computers & Security, 114, 102580. https://doi.org/10.1016/j.cose.2021.102580
Tang, Y. (2023). A Comprehensive Survey on Web Application Vulnerabilities Analysis and Detection. Computers & Security, 129, 103204. https://doi.org/10.1016/j.cose.2023.103204
Downloads
Published
How to Cite
Issue
Section
Citation Check
License
Copyright (c) 2026 Puji Zulaikasari, Avinanta Tarigan

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.













