Evaluating Web Security Resilience Using ISSAF: Evidence from a Public Village Information System
Keywords:
Web application security, ISSAF, penetration testing, vulnerability assessment, cybersecurity, e-government, network security, ethical hackingAbstract
The growing adoption of web-based public services has increased the cybersecurity risks faced by government information systems, particularly in small-scale environments with limited security resources. This study assesses the security of a village information system web application using the Information Systems Security Assessment Framework (ISSAF). The assessment was conducted through four stages: information gathering, network mapping, vulnerability assessment, and penetration testing. The findings indicate that the application has a moderate security posture. Information gathering revealed limited public exposure, although the lack of DNSSEC and accessible metadata presents potential security risks. Network mapping showed a small attack surface with only essential ports exposed. Vulnerability assessment identified several medium- and low-severity issues, mainly related to security misconfigurations such as missing HTTP security headers and weak cookie settings, while no critical vulnerabilities were detected. Penetration testing involving SQL injection, cross-site scripting (XSS), brute-force authentication, and denial-of-service simulations did not achieve successful exploitation, demonstrating the effectiveness of existing input validation and access control mechanisms. Overall, the application is resistant to common cyberattacks but remains vulnerable to multi-stage attacks caused by configuration weaknesses. These findings demonstrate the usefulness of ISSAF for evaluating web application security and provide practical recommendations for strengthening cybersecurity in resource-constrained e-government environments.
Downloads
References
A. Correa, R., Ram髇 Bermejo Higuera, J., Bermejo Higuera, J., Antonio SiciliaMontalvo, J., S醤chez Rubio, M., & Alberto Magre襻n, �. (2021). Hybrid Security AssessmentMethodology forWeb Applications. Computer Modeling in Engineering & Sciences, 126(1), 89–124. https://doi.org/10.32604/cmes.2021.010700
Alashwali, E. S., Szalachowski, P., & Martin, A. (2020). Exploring HTTPS security inconsistencies: A cross-regional perspective. Computers & Security, 97, 101975. https://doi.org/10.1016/j.cose.2020.101975
Allodi, L., Massacci, F., & Williams, J. (2022). The Work‐Averse Cyberattacker Model: Theory and Evidence from Two Million Attack Signatures. Risk Analysis, 42(8), 1623–1642. https://doi.org/10.1111/risa.13732
Altulaihan, E. A., Alismail, A., & Frikha, M. (2023). A Survey on Web Application Penetration Testing. Electronics, 12(5), 1229. https://doi.org/10.3390/electronics12051229
Auricchio, N., Cappuccio, A., Caturano, F., Perrone, G., & Romano, S. Pietro. (2022). An automated approach to Web Offensive Security. Computer Communications, 195, 248–261. https://doi.org/10.1016/j.comcom.2022.08.018
B, R. K., Godishala, A. K., Malaga, R. R., & Kagitapu, P. (2024). Securing web apps: Analysis to understand common vulnerabilities, attack scenarios, and protective measures. Proceedings of the 2024 10th International Conference on Computing and Data Engineering, 64–70. https://doi.org/10.1145/3641181.3641187
Berry, D. M. (2021). Empirical evaluation of tools for hairy requirements engineering tasks. Empirical Software Engineering, 26(6), 111. https://doi.org/10.1007/s10664-021-09986-0
Cheng, L., Liu, F., & Yao, D. (Daphne). (2017). Enterprise data breach: causes, challenges, prevention, and future directions. WIREs Data Mining and Knowledge Discovery, 7(5). https://doi.org/10.1002/widm.1211
Darojat, E. Z., Sediyono, E., & Sembiring, I. (2022). Vulnerability Assessment Website E-Government dengan NIST SP 800-115 dan OWASP Menggunakan Web Vulnerability Scanner. JURNAL SISTEM INFORMASI BISNIS, 12(1), 36–44. https://doi.org/10.21456/vol12iss1pp36-44
Disawal, S., & Suman, U. (2023). An Approach to Detect and Prevent SQL Injection and XSS Vulnerability in the Web Application. International Journal of Engineering Trends and Technology, 71(8), 216–224. https://doi.org/10.14445/22315381/IJETT-V71I8P219
García, S., Grill, M., Stiborek, J., & Zunino, A. (2014). An empirical comparison of botnet detection methods. Computers & Security, 45, 100–123. https://doi.org/10.1016/j.cose.2014.05.011
Holz, R., Amann, J., Mehani, O., Wachs, M., & Kaafar, M. A. (2016). TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic Communication. 23rd Annual Network and Distributed System Security Symposium, NDSS 2016. https://doi.org/10.14722/ndss.2016.23055
Lachkov, P., Tawalbeh, L., & Bhatt, S. (2022). Vulnerability Assessment for Applications Security Through Penetration Simulation and Testing. Journal of Web Engineering. https://doi.org/10.13052/jwe1540-9589.2178
Roth, S., Barron, T., Calzavara, S., Nikiforakis, N., & Stock, B. (2020). Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies. Proceedings 2020 Network and Distributed System Security Symposium. https://doi.org/10.14722/ndss.2020.23046
Sabottke, C., Suciu, O., Dumitraş, T., & Dumitras, T. (n.d.). Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits. Retrieved https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/sabottke
Sasaki, T., Fujita, A., Gañán, C. H., van Eeten, M., Yoshioka, K., & Matsumoto, T. (2022). Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management Devices. 2022 IEEE Symposium on Security and Privacy (SP), 2379–2396. https://doi.org/10.1109/SP46214.2022.9833730
Wen, S.-F., & Katt, B. (2023). A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standard. Computers & Security, 135, 103532. https://doi.org/10.1016/j.cose.2023.103532
Zhang, H., Ye, J., Hu, W., Wang, Q., Yan, X., Yue, Q., Lv, W., He, M., & Wang, J. (2021). Study on the latent state of Kaminsky-style DNS cache poisoning: Modeling and empirical analysis. Computers & Security, 110, 102445. https://doi.org/10.1016/j.cose.2021.102445
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Putra Prasetya, Harjono, Mukhlis Prasetyo Aji, Ermadi Satriya Wijaya

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
