The article aims to describe the children's faith education on comparison of Abdullah Nashih Ulwan and Zakiah Daradjat Thoughts. The research methodology applied in this study is literature review, also known as library research. Primary data sources consist of works by Abdullah Nashih Ulwan, such as "Tarbiyatul Aulad Fil Islam: Pendidikan Anak Dalam Islam," and works by Zakiah Daradjat, such as "Islam dan Kesehatan Mental," "Ilmu Jiwa Agama," "Pendidikan Islam dalam Keluarga dan Sekolah," and "Ilmu Pendidikan Islam." Secondary data sources involve other relevant books on the topic. The data analysis method employed is content analysis. From the author's research, the thoughts of Abdullah Nashih Ulwan and Zakiah Daradjat on faith education encompass both content and methods. There is a similarity in the thoughts of these two figures, specifically in terms of the content of faith education, the use of the concept of tawhid to guide children's lives, instilling worship habits, educating children about muraqabatullah, and employing exemplary and habituation methods. At the same time, there are differences in the use of punishment in education; Abdullah Nashih Ulwan allows punishment but focuses on methods taught by Islam, while Zakiah Darajat does not use punitive education in child upbringing. Keywords: Children's Faith Education, Abdullah Nashih Ulwan Thoughts, Zakiah Daradjat Thoughts
As with crimes that occur in the real world, cybercrime cases require investigation to gather evidence for court proceedings. Digital forensics is a great way to investigate evidence from cybercrime. Investigating a cybercrime to find digital evidence cannot be done inappropriately. Mishandling of evidence can make it invalid. It is necessary to copy the evidence before, so the investigation process is not done directly on the original digital evidence. Intended to avoid or at least minimize damage to evidence. In conducting an investigation, an investigator needs tools and supporting devices that have high accuracy, reliable, and affordable. However, most of the devices on the market are available at quite expensive prices. Therefore, in this study, performed design and construction of a low-cost disk imaging device were carried out using the Raspberry Pi 4 and implemented using Python languages to copy evidence in the digital forensics process. Testing results and analysis of the proposed device show a good performance in terms of speed and accuracy of copies.
The rapid growth of digital systems and the increasing demand for secure and reliable identity management have driven the need for a robust blockchain architecture specifically designed for Indonesia’s national identity management system, known as IDNat-Blockchain. This research paper proposes a blockchain architecture that addresses the unique challenge faced by Indonesia in managing its vast population and diverse digital economy. The design incorporates multiple layers, including the hardware/infrastructure layer, network layer, consensus layer, and application layer, to ensure a secure, scalable, and interoperable system. This research paper focuses on the design and implementation of a robust blockchain architecture specifically tailored for IDNat-Blockchain, the Indonesia’s National Blockchain system. Our research found that the best-fit network for IDNat-Blockchain is private network, consortium network for IDGov-Blockchain and IDVII-Blockchain, and hybrid network for IDPub-Blockchain. We also found that Proof of Authority (PoA) combined with Practical Byzantine Fault Tolerance (PBFT) for IDNat-Blockchain, IDGov-Blockchain, IDVII-Blockchain, and IDPub-Blockchain. Layer 0 would fit to IDNat-Blockchain, Layer 1 for IDGov-Blockchain, Layer 1 combined with Layer 2 for IDVII-Blockchain, and Layer 1, Layer 2, and Layer 3 combination for IDPub-Blockchain. The choices highlight its security, decentralization, scalability, energy consumption, complexity, efficiency, transparency, cost, user, immutability, and speed consideration.
Pada Institut XYZ, unit kerja yang memiliki tanggung jawab untuk mengelola layanan teknologi informasi dan pusat data adalah Unit TI. Berdasarkan Peraturan Pemerintah Nomor 71 Tahun 2019, untuk menanggulangi dampak kehilangan layanan pada pusat data yang disebabkan oleh bencana dan ancaman, diperlukan adanya rencana yang bertujuan untuk mencegah kehilangan dan kerusakan, yaitu rencana pemulihan bencana atau DRP. Hal tersebut didukung dengan kuesioner dan wawancara yang dilakukan kepada jajaran pejabat struktural, kepala unit dan mahasiswa Institut XYZ yang menyatakan bahwa layanan yang dikelola oleh Unit TI XYZ bersifat vital bagi proses bisnis perkuliahan, administrasi umum dan kemahasiswaan. Pada tahun 2021, terjadi kegagalan pada pusat data Unit TI XYZ yang menyebabkan proses perkuliahan daring dan administrasi terhenti karena portal daring yang tidak dapat diakses dan hilangnya data yang disimpan pada penyimpanan awan. Berdasarkan hal tersebut, dilakukan perancangan rencana pemulihan bencana menggunakan NIST SP 800-34 Rev 1 sebagai kerangka kerja penyusunan DRP, NIST SP 800-53 Rev 5 sebagai kendali pencegahan, dan SNI 8799 sebagai acuan persyaratan pusat data. Sebagai hasilnya, disusun enam rencana pemulihan untuk sistem dengan prioritas tinggi, tiga rencana pemulihan untuk sistem dengan prioritas sedang, dan dua rencana pemulihan untuk sistem dengan prioritas rendah. Abstract At the XYZ Institute, the work unit responsible for managing information technology and data center services is the IT Unit. According to Government Regulation Number 71 of 2019, to overcome the impact of service loss in data centers caused by disasters and threats, it is necessary to have a plan that aims to prevent loss and damage, namely a disaster recovery plan or DRP. This is supported by questionnaires and interviews with structural officials, unit heads, and students of the XYZ Institute, which state that services managed by the IT Unit XYZ are vital for the business processes of lectures, general administration, and student affairs. In 2021, there was a failure in the IT Unit XYZ data center, which caused the online lecture and administration process to stop due to an inaccessible online portal and loss of data stored in cloud storage. Based on the regulation requirement, interviews, and questionnaires, a disaster recovery plan was designed using NIST SP 800-34 Rev 1 as a framework for preparing the DRP, NIST SP 800-53 Rev 5 as a preventive control, and SNI 8799 as a reference for data center requirements. As a result, six recovery plans were developed for high-priority systems, three recovery plans for medium-priority systems, and two recovery plans for low-priority systems.
Untuk mendukung fungsinya sebagai instansi pemerintahan, Instansi Pemerintah ABC menggunakan layanan teknologi informasi (TI) untuk membantu proses bisnis dan penyediaan layanan publik. Untuk mendapatkan hasil yang maksimal dari penggunaan TI, diperlukan adanya rencana tata kelola dan manajemen terhadap TI sehingga penggunaanya dapat sejalan dengan tujuan dan capaian yang diinginkan dari instansi. Pada penelitian ini, dilakukan perancangan rencana tata kelola dan manajemen TI untuk Instansi Pemerintah ABC dengan menggunakan kerangka kerja COBIT 2019 dan kendali dari NIST SP 800-53 Rev 5. Hasilnya, terdapat 9 proses dari COBIT 2019 dan 14 kendali dari NIST SP 800-53 Rev 5 yang dapat diterapkan oleh Instansi Pemerintah ABC sebagai rencana tata kelola dan manajemen TI.
Many workers need multiple applications to carry out their works. The number of applications makes users have to set several accounts and passwords for various application services. This creates complexity in managing it manually so that users switch to using password manager applications, both free and paid. KeePass, KeePassXC, and Password Safe are three examples of open-source password manager applications developed as low-cost solution. In general, open-source password manager applications have disadvantages compared to similar paid applications. Analysis of open-source password manager applications is necessary to find out their specifications, advantages, and disadvantages so that they can be taken into consideration by users in choosing a suitable password manager application. In this study, a comparative analysis of three open-source, Windows-based password manager applications i.e., KeePass, KeePassXC, and Password Safe was carried out using the Usability, Performance, and Security parameters based on ISO/IEC 25010. The result of this study indicates that on the parameter of Usability, the KeePassXC excels in all six categories. In parameter of Performance, the Password Safe excels in one category, the KeePass also excels in one category, and the KeePassXC and Password Safe are equivalent in one category. Furthermore, on parameter of Security, KeePass outperformed others in one category and for the rest four categories, all applications are equivalent.
Pada saat ini telah banyak dirancang aplikasi instant messenger untuk mendukung dan memudahkan aktivitas komunikasi. Salah satu aplikasi tersebut adalah PeSankita, yang merupakan salah satu produk instant messenger buatan Indonesia. Produk instant messenger perlu dievaluasi keamanannya agar terbentuk kepercayaan pengguna terhadap keamanan data, baik yang disimpan ataupun dipertukarkan menggunakan aplikasi tersebut. Salah satu standar yang dapat digunakan untuk melakukan evaluasi keamanan produk secure chat adalah Common Criteria for IT Security Evaluation Version 3.1 Revision 5:2017 (CC). Metode yang dapat digunakan untuk melakukan pengujian produk tersebut adalah Common Criteria Evaluation Methodology Version 3.1 Revision 5:2017 (CEM). Pada penelitian ini telah dilakukan evaluasi aplikasi PeSankita pada kelas Assurance Vulnerability Assessment (AVA) yaitu kelas penilaian kerentanan yang mungkin terdapat dalam PeSankita sebagai Target of Evaluation (TOE). Evaluasi dilakukan berdasarkan data mengenai TOE yang telah didapatkan sebelumnya. Hasil yang didapatkan dari proses pengujian yang disertai dengan bukti evaluasi menunjukkan bahwa TOE, dalam hal ini PeSankita, tidak memenuhi klaim dari pihak pengembang dan gagal dalam pengujian yang dilakukan karena PeSankita versi 1.4.23 tidak mampu memitigasi tingkat serangan dasar pada pengujian client code quality dan reverse engineering
The digital forensic readiness of an organization shows the readiness level of the organization in dealing with cybercrimes. To measure the digital forensic readiness of an institute or organization, a digital forensic assessment tool is needed. There is a digital forensic readiness assessment model proposed by Widodo called the Digital Forensic Readiness Index (DiFRI). This model has been applied to assess the readiness of digital forensics at the Computer and Information Systems Center of Sunan Kalijaga State Islamic University in Indonesia. The DiFRI model can be used to measure the digital forensic readiness level of cyber organizations. In this study, we measured the digital forensic readiness of a cyber organization called XYZ using the DiFRI model. The measurement results show that the XYZ got a digital forensic readiness index value of 2.33 from a perfect score of 10.00. This value indicates that the XYZ is in the category of “Not Ready” in digital forensic readiness. Based on the analysis of indicators on digital forensic readiness, recommendations are given for each indicator aimed at increasing digital forensic readiness while increasing the value of the DiFRI index at XYZ.
Elementary school students are a group with a high risk of dental caries, so their selection as a target for health promotion is very appropriate. This research aims to develop accessible, cheap, and effective health promotion media. Health promotion media developed are audiovisual and leaflets. The research method is a quasi-experimental (quasi- experimental) design with a pre-test – post-test group design. The population in this study was all students of Beureunun State Elementary School I and all of Beureunun State Elementary School 3, Pidie Regency. The sample in the study amounted to 100 students. Data analysis used univariate and bivariate. The study's results found a difference in the mean knowledge score in post-test I and post-test II between the audiovisual media group and the leaflet media group. The audiovisual media group was higher than the leaflet statistically at the significance level of p = 0.000. In the attitude aspect, there is a difference in the mean attitude score in post-test I and post-test II; audiovisual media showed an increase in the mean score of attitudes which was higher than the leaflet group, which was proven statistically at a significant level of p = 0.000. There is a difference in the mean behavioral score in post-test I and post-test II between the audiovisual media group and the leaflet media group, the mean behavior score in the audiovisual media group are higher than the leaflet at a significance level of p = 0.000.
The COVID-19 pandemic has forced us to make many work adjustments in our daily life like work from home, school from home, shop form home and many remote activities. Work from home activity present both new security opportunities and loopholes. Virtual Private Network (VPN) is one solution for such remote activities. However, VPN products may be confusing for users due to their complexity and user unfriendliness. Fortunately, there existed Wireguard, which is kernel structure of VPN module, that balances in security and ease to use. Embedded system using Raspberry pi armed with VPN Wireguard and equipped with Security Information and Event Management (SIEM) Suricata being one of the solutions to overcome it. In this study, we tried hardening a Work from home network using Wireguard and Suricata. Combination of ease to use in compact hardware and hardening with Interruption Detection System (IDS) give capability result for operation with 18,7% CPU and 22,7% memory usage and protection with captured 100% event port scanning and exploit.
Currently, HTTPS is commonly used because it offers more protection when compared to HTTP. However, it does not rule out the possibility of attacks being carried out against HTTPS. One of the features that can improve HTTPS security is configuring HTTP strict transport security (HSTS). Unfortunately, not all HSTS is successfully configured and implemented correctly due to administrator ignorance. The purpose of this study is to provide an overview of what configurations need to be done to run HSTS properly to increase the functionality of existing features and improve security. Configuration conformity testing is done using three parameters, i.e., max-age, includeSubDomains, and preload. The attack attempts carried out in this exploratory study used Bettercap, which allows multiple types of attacks to be carried out simultaneously. The results obtained from this study include a list of parameters that need to be met as a condition of an adequately configured HSTS on a website, such as the max-age value, which has a minimum value of 31536000.
Spesifikasi keamanan sangat penting bagi pengembangan aplikasi chatting karena dapat menentukan tingkat keamanan aplikasi yang tentunya akan berdampak pada kepercayaan pengguna. Namun, pengembangan fitur keamanan pada aplikasi yang beredar belum semua didasarkan pada suatu spesifikasi kebutuhan keamanan yang jelas. Misanya, aplikasi Mxit dan QQ Mobile tidak memenuhi satu pun dari tujuh kategori keamanan untuk secure chat yang dikeluarkan oleh Electronic Frontiers Foundtaion (EFF). Bahkan, Yahoo! Messenger belum menerapkan disain keamanan yang baik, misalnya kita tidak dapat memverifikasi identitas kontak kita. Selain itu, Yahoo! Messenger tidak menerapkan perfect forward secrecy. Artinya, fitur keamanan pada beberapa aplikasi chat dikembangkan tidak berdasarkan pada rancangan spesifikasi keamanan. Pada penelitian ini, dilakukan perancangan spesifikasi keamanan untuk pengembangan aplikasi secure chat dengan mengacu pada Common Criteria for IT Security Evaluation Version 3.1:2017. Pada hasil rancangan tersebut, telah ditentukan 28 famili dari 7 kelas Secure Functional Requirement (SFR) yang harus dipenuhi dalam pengembangan aplikasi secure chat. Hasil rancangan telah divalidasi dengan metode expert judgment. Abstract Security specifications are very important for chat application development because they can determine the level of its security which, of course, will have an impact on user trust. However, the development of outstanding application security features is not all based on a clear security requirement specification. For example, the Mxit and QQ Mobile applications do not meet any of the seven security categories for secure chat issued by the Electronic Frontier Foundation (EFF). In fact, Yahoo! Messenger has not implemented a good security design, for example, we cannot verify the identity of our contacts and do not apply perfect forward secrecy. This means that security features in some chat applications are developed not based on security specification designs. In this study, the design of security specifications for secure chat application development was carried out by referring to the Common Criteria for IT Security Evaluation Version 3.1: 2017. In the design results, 28 families of 7 classes of Secure Functional Requirements (SFR) have been determined that must be met in the development of secure chat applications. The design result has been validated using expert judgment method.
Purpose: Malicious software or malware is a real threat to the security of computer systems or networks. Researchers made various attempts to find information and knowledge about malware, including preventing or even eliminating it. One effort to detect it is using a malware dynamic analysis model based on reverse engineering techniques. However, there are many reverse engineering techniques proposed with various stages and requirements in the literature. Methods: This research uses an experimental method. The object of research is a malware analysis model using reverse engineering techniques. The experimental method used is qualitative, collecting data related to the advantages and disadvantages of the reverse engineering-based malware analysis models used as a reference in this study. The data is used as consideration to propose a new model of malware analysis utilizing reverse engineering techniques. Result: In this study an analysis model of malware was proposed by synthesizing several reverse engineering-based malware analysis models. Novelty: The proposed model was then tested in a virtual environment where it is proven to be more effective than previous models for analyzing malware.
Aplikasi ABC adalah sebuah aplikasi mobile berbasis Android yang digunakan oleh instansi XYZ. Aplikasi tersebut digunakan untuk layanan pengajuan daring pada bidang XXX. Seiring meningkatnya popularitas aplikasi berbasis Android, meningkat pula masalah keamanan yang perlu diperhatikan, seperti insecure data storage yang merupakan kerawanan tertinggi. Pada penelitian ini, dilakukan uji keamanan aplikasi mobile berbasis Android yang disebut ABC berdasarkan OWASP Mobile Security Testing Guide. Pengujian dilakukan dengan pendekatan grey box pada cakupan fokus area Data Storage on Android dan Local Authentication on Android di level 1. Pengujian terdiri dari delapan bagian pengujian. Berdasarkan hasil dari delapan pengujian yang telah dilakukan, ditemukan tiga kerentanan pada bagian Testing Local Storage for Sensitive Data, Testing Local Storage for Input Validation, dan Determining Whether the Keyboard Cache Is Disabled for Text Input Fields. Rekomendasi perbaikan yaitu memberikan pengamanan enkripsi di file shared preferences, melakukan validasi input pada akun pengguna, dan aplikasi tidak menyimpan cache.
With the use of information systems as a means for supporting the success of missions and objectives of organizations increased, the protection towards assets against cyber risks needs to be considered and paid more attention. Cyber-risk management planning can be carried out as a means or approach to protect assets from the risks of cyber-attacks. As a supporting unit in XYZ, the IT Unit has the responsibility to manage the information systems, information technology, and their infrastructure and services within the XYZ system. However, the IT Unit has never conducted a cybersecurity evaluation so it does not yet have a plan for cybersecurity risk management. In this study, we tailored a cyber-risk plan for the IT Unit of XYZ using NIST CSF as the main framework and CIS Controls v8 and NIST SP 800-53 Rev 5 for defining controls and action recommendations. As the results, we found 42 risk scenarios in the IT Unit in which 12 are accepted and 30 are mitigated. There are 14 actions recommendation for the IT Unit to reach tier 3 based on 18 controls of CIS and 20 controls of NIST SP 800-53 rev 5 that can be applied to control the current cyber-risk.
This paper discusses the forms of academic communication of Islamic religious education teachers in Improving Student Learning Interest in Limua Dapurang Elementary School, Dapurang District, Pasangkayu Regency. This study used a case study approach. Data collection techniques in this study using observation, interviews and documentation. Data analysis techniques through data reduction analysis, data presentation and data verification that ends with checking the validity of the data with the source triangulation method. The results showed that the forms of Academic communication of Islamic education teachers in increasing the learning interest of the students regarding interpersonal communication which includes approaching, giving advice, exemplary, and reward. Second, group communication includes explaining the material gently, decisively and attractively, motivating and increasing the activeness of students and providing habituation. The results of increasing students' interest in learning caused students doing assignment diligently, hard studying, and increase student grades. The supporting factors include the teacher's ability to communicate, a willingness of students to receive advice and the support of class teachers. While the inhibiting factors are the level of understanding and response power of students and the lack of support from parents.
For cybersecurity activists, reviewing whether an application, including modified applications, is malicious or not is a challenging job. WhatsApp Plus is a messenger application modified from the official WhatsApp application. Comparing the source code of the WhatsApp Plus with the official WhatsApp is one way to review its security or malice. Considering that WhatsApp is very popular and has many users, the results of this investigation are very useful for users to avoid malicious applications. In this study, we have conducted an exploration of the source code of the WhatsApp and WhatsApp Plus applications to find out whether or not WhatsApp Plus has been inserted with malware, spyware, or other malicious code. The exploration used the static analysis method, where the source code of the two applications were decompiled, compared, and analyzed. The de-compilation is done using the MobSF tool and the comparison using the extension of Visual Studio Code called Compare Folders. The differences in the source code found are then analyzed for possible behavior to determine whether it can cause harm, for example stealing user credentials. Although no malicious code was found on WhatsApp Plus, in our study, users must stay alert since they remain vigilant in installing and using WhatsApp Plus because the developer may add malicious code to the next version update.
Convenience often comes with the price of security. As our research results in strengthening the opinion, we should reconsider the action of sacrificing security over convenience. One of those convenience that are readily available in almost any Android smartphone is the Smart Lock Trusted Place feature. By conditioning the smartphone in order to disable GPS satellite signals and creating a Wi-Fi hotspot with Wireless Positioning System, we are able to deceive the device that it is in the designated trusted place thus unlocking the phone.
The increasing number of smartphone users will encourage competition among smartphone manufacturers in innovating and marketing their products. Such competition can create open space for attackers to understand how smartphones work and then spread threats through malicious programs. In this study, a brief review of various threats and mitigations is carried out on smartphones infrastructure, especially on several well-known brand smartphones.
Game-based learning, both in the form of serious games and gamification, has developed rapidly and penetrated various fields of science and it is believed by some that it can increase the human ability to learn various things, increase the effectiveness and efficiency of a job, collaboration, and positive attitudes. To be able to choose the right game as needed, a summary of knowledge about the game and its application is needed. However, to see more broadly the application of the game in various fields and the various aspects that accompany it, it takes time and effort to study and summarize it from the various existing literature, which is sometimes difficult for those who have a busy life. For this reason, in this study, a brief systematic literature review was carried out on the application of games based on several aspects using the latest literature using the DICARe method. Several research questions were asked to be answered through this literature review. The results show that the most widely proposed research objective is to study the effects of serious play or gamification in the learning field. However, there is another research objective, which is to help detect fake content, which, although it seems less significant, is very relevant to today's human life who is fond of social media. Furthermore, the area most discussed is the field of subject learning in classrooms and the most widely used assessment parameter is user experience. No type of play is overly dominant with the ratio between multi-player and single-player being 57:43. This shows that the type of game chosen to use really depends on the goals to be achieved. The results of this study are expected to provide insight and become a reference for readers in developing game-based methods.