Pola Kerentanan Aplikasi Endpoint pada Sektor Manufaktur dan Ritel di Indonesia

Darren Valentio, Erick Dazki

Abstract


Penelitian ini bertujuan untuk menganalisis dan membandingkan pola kerentanan aplikasi endpoint pada dua sektor industri strategis di Indonesia, yaitu manufaktur dan ritel. Studi ini menggunakan data aktual dari lebih dari 1.200 endpoint, yang terdiri atas 1.000+ endpoint dari perusahaan manufaktur dan 200+ endpoint dari perusahaan ritel, yang dimonitor melalui platform Endpoint Detection and Response (EDR) SentinelOne selama periode Februari 2023 hingga Maret 2025. Keren-tanan diidentifikasi berdasarkan entri CVE (Common Vulnerabilities and Exposures) dan diklasifikasikan menurut tingkat keparahan menggunakan standar CVSS v3.1. Analisis dan visualisasi dilakukan terhadap distribusi severity, jumlah CVE per aplikasi, dan jumlah end-point terdampak di masing-masing sektor. Hasil menunjukkan bahwa sektor manufaktur lebih banyak terdampak oleh aplikasi produktivitas dan sistem legacy, sedangkan sektor ritel lebih rentan terhadap aplikasi remote access lawas dan framework .NET yang tidak lagi didukung. Penelitian ini juga membandingkan temuan dengan tren global dan menyusun strategi mitigasi sektoral yang kontekstual dan adaptif, ber-dasarkan best practices seperti NIST SP 800-40 dan Microsoft Security Baseline. Temuan ini diharapkan dapat menjadi landasan awal bagi kebijakan keamanan siber yang lebih berbasis data dan sesuai karak-teristik sektor industri di Indonesia.

Keywords


Keamanan Aplikasi Endpoint; SentinelOne; Manufaktur; Ritel; Kerentanan Aplikasi End-point

Full Text:

PDF

References


M. Alsharif, S. Mishra, and M. AlShehri, “Impact of Human Vulnerabilities on Cybersecurity,” Computer Systems Science and Engi-neering, vol. 40, no. 3, pp. 1153–1166, Sep. 2021, doi: 10.32604/CSSE.2022.019938.

W. S. Admass, Y. Y. Munaye, and A. A. Diro, “Cyber security: State of the art, challenges and future directions,” Jan. 01, 2024, KeAi Communications Co. doi: 10.1016/j.csa.2023.100031.

Ö. Aslan, S. S. Aktuğ, M. Ozkan-Okay, A. A. Yilmaz, and E. Akin, “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions,” Mar. 01, 2023, MDPI. doi: 10.3390/electronics12061333.

A.Shaji George, S.Sagayarajan, T.Baskar, and A.S.Hovan George, “Extending Detection and Response How MXDR Evolves Cyberse-curity,” Partners Universal International Innovation Journal (PUIIJ), 2023.

G. Karantzas and C. Patsakis, “An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors,” Journal of Cybersecurity and Privacy, vol. 1, no. 3, pp. 387–421, Sep. 2021, doi: 10.3390/jcp1030021.

H. Kaur et al., “Evolution of Endpoint Detection and Response (EDR) in Cyber Security: A Comprehensive Review,” in E3S Web of Conferences, EDP Sciences, Aug. 2024. doi: 10.1051/e3sconf/202455601006.

F. Dong et al., “Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response Tools,” in CCS 2023 - Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery, Inc, Nov. 2023, pp. 2396–2410. doi: 10.1145/3576915.3616580.

V. Mullet, P. Sondi, and E. Ramat, “A Review of Cybersecurity Guidelines for Manufacturing Factories in Industry 4.0,” 2021, Insti-tute of Electrical and Electronics Engineers Inc. doi: 10.1109/ACCESS.2021.3056650.

N. Gupta, A. Tiwari, S. T. S. Bukkapatnam, and R. Karri, “Additive Manufacturing Cyber-Physical System: Supply Chain Cybersecu-rity and Risks,” IEEE Access, vol. 8, pp. 47322–47333, 2020, doi: 10.1109/ACCESS.2020.2978815.

A. Jan and A. Vaish, “CYBER SECURITY FOR DIGITAL MANUFACTURING,” International Journal of Technical Research & Sci-ence, pp. 27–29, Dec. 2021, doi: 10.30780/ijtrs.v06.i12.005.

F. Fauziyah, Z. Wang, and G. Joy, “Knowledge Management Strategy for Handling Cyber Attacks in E-Commerce with Computer Se-curity Incident Response Team (CSIRT),” Journal of Information Security, vol. 13, no. 04, pp. 294–311, 2022, doi: 10.4236/jis.2022.134016.

M. T. Islam, Md. F. Islam, and J. Sawda, “E-Commerce and Cyber Vulnerabilities in Bangladesh A Policy Paper,” International Jour-nal of Law and Society, 2022.

Z. Wang, H. Zhu, and L. Sun, “Social engineering in cybersecurity: Effect mechanisms, human vulnerabilities and attack methods,” IEEE Access, vol. 9, pp. 11895–11910, 2021, doi: 10.1109/ACCESS.2021.3051633.

R. Ramirez, C. K. Chang, and S. H. Liang, “PLC Cybersecurity Test Platform Establishment and Cyberattack Practice †,” Electronics (Switzerland), vol. 12, no. 5, Mar. 2023, doi: 10.3390/electronics12051195.

A. S. George, A. s H. George, and D. T. Baskar, “XDR: The Evolution of Endpoint Security Solutions-Superior Extensibility and Ana-lytics to Satisfy the Organizational Needs of the Future,” International Journal of Advanced Research in Science Communication and Technology, 2021, doi: 10.5281/zenodo.7028219.

Kementerian Perindustrian Republik Indonesia, “Making Indonesia 4.0: Roadmap for Indonesia’s Industrial Future,” 2018. Accessed: Jun. 07, 2025. [Online]. Available: https://bsn.go.id/uploads/download/making_indonesia_4.0_-_kementerian_perindustrian.pdf

T. and B. & C. Google, “e-Conomy SEA 2022: Through the Waves, Towards a Sea of Opportunity,” 2022. Accessed: Jun. 07, 2025. [Online]. Available: https://www.temasek.com.sg/content/dam/temasek-corporate/news-and-views/resources/reports/e_Conomy_SEA_2022_report.pdf

IBM Security / Red Hat, “IBM X-Force Threat Intelligence Index 2025,” 2025. Accessed: Jun. 08, 2025. [Online]. Available: https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2025-threat-intelligence-index

Microsoft Security, “Digital Defense Report 2023,” 2023. Accessed: Jun. 08, 2025. [Online]. Available: https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023

SecurityWeek and Brian Prince, “Weak Remote Access Practices Contributed to Nearly All PoS Breaches: Trustwave,” 2015. Ac-cessed: Jun. 08, 2025. [Online]. Available: https://www.securityweek.com/weak-remote-access-practices-contributed-nearly-all-pos-breaches-trustwave/

Barracuda Networks and Jonathan Tanner, “Threat Spotlight: The remote desktop tools most targeted by attackers in the last year,” 2024. Accessed: Jun. 08, 2025. [Online]. Available: https://blog.barracuda.com/2024/05/01/threat-spotlight-remote-desktop-tools-most-targeted

Scott Rose, Oliver Borchert, Stu Mitchell, and Sean Connelly, “Zero Trust Architecture,” 2020. Accessed: Jun. 09, 2025. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf




DOI: https://doi.org/10.29100/jipi.v11i2.8114

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika)
ISSN 2540-8984
Published by
Prodi Pendidikan Teknologi Informasi
Universitas Bhinneka PGRI

Website :https://jurnal.stkippgritulungagung.ac.id/index.php/jipi/index
Email: jipistkippti@gmail.com


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.