Skip to content
Open access

Security Analysis and Threat Modeling of the Informatics Engineering Laboratory Information System (SILABTI) Using Attack Tree Methodology

Aug 2026 · International Journal for Sciences and Technology · Vol 5, pp. 323-336 · 0 citations · 7 references

TL;DR

The findings indicate that SILABTI's security risks arise from the interaction of legacy software, network communication weaknesses, endpoint privileges, authentication controls, and human factors, and this framework can guide university IT administrators in strengthening legacy academic information systems.

Abstract

Academic information systems manage sensitive data whose integrity directly affects academic administration and student outcomes. Legacy intranet-based systems may remain vulnerable to both technical attacks and human-factor threats, particularly when outdated software, unencrypted communication, weak access controls, and privileged user access coexist within the same operational environment. Objective: This study aims to analyze the security vulnerabilities of the Informatics Engineering Laboratory Information System (SILABTI) and identify potential pathways for unauthorized modification of practicum grades and graduation statuses using a hierarchical Attack Tree approach. Methodology: This study employed an analytical systems-engineering design based on Attack Tree threat modeling. The assessment covered the SILABTI web application, local network environment, MySQL database architecture, and administrative workflows. System boundaries and technical conditions were identified through infrastructure assessment and network reconnaissance, followed by hierarchical decomposition of adversarial objectives into root goals, intermediate sub-goals, and technical execution leaf nodes using AND/OR relationships. The resulting attack pathways were qualitatively evaluated according to technical prerequisites, execution complexity, system exposure, and detection probability. Findings: The analysis identified four primary intrusion vectors: credential acquisition, application exploitation, database exploitation, and insider exploitation. Four pathways were considered particularly high-risk: local network sniffing, workstation keylogging, automated brute-force attacks, and insider bribery or coercion. These findings indicate that SILABTI's security risks arise from the interaction of legacy software, network communication weaknesses, endpoint privileges, authentication controls, and human factors. Implications: The findings support an eight-point defense-in-depth framework incorporating TLS/HTTPS, tamper-resistant audit logging, role-based access control, network access restrictions, stronger authentication controls, workstation privilege restriction, anti-spoofing measures, and institutional security governance. This framework can guide university IT administrators in strengthening legacy academic information systems. Originality: This study contributes a hierarchical threat-decomposition model specifically designed for a legacy intranet-based academic laboratory information system, integrating technical and human-layer attack pathways within a single security assessment framework.

Read PDF

Similar papers

Review Open access Aug 2026

Cloud Security Challenges and Risk Management in Modern Cloud Computing Environment

The study demonstrates that the key factors to achieving effective cloud security are continuous monitoring, robust governance policies, employee awareness training, and high-level cybersecurity frameworks.

Veeramani Sampathkumar, Dinesh Kumar Ramaraj, Rajesh Kotha et al. · 0 citations
Open access 2026

Web application security using top 10 OWASP

It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.

S. Banu, H. Shanmatha, Mehdi Gheisari et al. · 0 citations
2026

Integration of Vulnerability Databases into ISMS: A Path to Enhancing Cyber Resilience of Critical Systems

A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cy...

V. Yashchuk, A. Ivanusa, N. Maslova et al. · 1 citation
#artificial intelligence Open access Nov 2026

A network-based security information system for safeguarding computer-based test platforms in organizational environments

Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and...

Ajani Dele, Owolabi Abdulhakim Adewale, Inaya Adesuwa · 0 citations
Review Open access Aug 2026

Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems

A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.

Mohammed AbuTaha · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.