Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

Vulnerability Analysis of E-voting Application using Open Web Application Security Project (OWASP) Framework

Author 1: Sunardi Author 2: Imam Riadi Author 3: Pradana Ananda Raharja
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 10, No. 11 · Published 2019 · Cited by 25

DOI: https://doi.org/10.14569/IJACSA.2019.0101118

Abstract

This paper reports on security concerns in the E-voting used for the election of village heads. Analysis of the system and server uses two different tools to determine the accuracy of scanning vulnerabilities based on the OWASP Framework. We reported that the results of the scanning using the ZAP tool got vulnerability information with the following risk level, one high level, three medium levels, and eleven low levels. The Arachni tool got vulnerability information with the following risk level, one high level, three medium levels, and two low levels. ZAP has a more complex vulnerability view than Arachni. Fatal findings on E-voting in this E-voting system is XSS, which impacts clients, which can be exploited by attackers to bypass security. Directory Traversal allows attackers to access directories and can execute commands outside of the web server’s base directory. Cyber Hiscox Readiness report in 2018 in several European countries such as The United States, Britain, Germany, Spain, and the Netherlands, that the Attackers target through the most vulnerable security holes such as injection, Broken Authentication, Sensitive Data Exposure, XXE, Merged, Security Misconfiguration, XSS, Insecure Deserialization, Using Components with Known Vulnerabilities, Insufficient Logging, and Monitoring. The purpose of cyberattacks alone can threaten the stability of the country and disturb other factors. E-voting, as part of an electronic government system, needs to be audited in terms of security, which can cause the system to disrupt.

Keywords

How to Cite this Article

Sunardi, Riadi, I., & Raharja, P. A. (2019). Vulnerability Analysis of E-voting Application using Open Web Application Security Project (OWASP) Framework. International Journal of Advanced Computer Science and Applications, 10(11). https://doi.org/10.14569/IJACSA.2019.0101118

Sunardi, et al.. "Vulnerability Analysis of E-voting Application using Open Web Application Security Project (OWASP) Framework." International Journal of Advanced Computer Science and Applications, vol. 10, no. 11, 2019, https://doi.org/10.14569/IJACSA.2019.0101118.

@article{Sunardi2019,
  title     = {Vulnerability Analysis of E-voting Application using Open Web Application Security Project (OWASP) Framework},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {10},
  number    = {11},
  year      = {2019},
  publisher = {The Science and Information Organization},
  author    = {Sunardi and Imam Riadi and Pradana Ananda Raharja},
  doi       = {10.14569/IJACSA.2019.0101118},
  url       = {https://doi.org/10.14569/IJACSA.2019.0101118}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.