Analisis Risiko Roundcube Debian dengan CVSS dan Random Forest

Authors

  • Evaldo Manurung Universitas Katolik Santo Thomas
  • Christin Sigiro Universitas Katolik Santo Thomas
  • Lotar Mateus Sinaga Universitas Katolik Santo Thomas

DOI:

https://doi.org/10.31004/riggs.v5i2.11597

Keywords:

Roundcube, Debian 12, CVSS, Random Forest, Keamanan Mail Server

Abstract

Penelitian ini menganalisis risiko keamanan Roundcube Mail Server pada Debian 12 melalui perbandingan kondisi sebelum dan sesudah penerapan keamanan dasar. Lingkungan pengujian dibangun pada jaringan lokal menggunakan domain evaldo.com agar konfigurasi server, client, dan koneksi dapat dikendalikan. Data dikumpulkan melalui validasi akses webmail, uji pengiriman dan penerimaan email, pemindaian port menggunakan Nmap, audit sistem menggunakan Lynis, pengujian web server menggunakan Nikto, serta pencatatan status UFW, Fail2Ban, dan Zabbix Agent. Setiap temuan teknis dinilai menggunakan Common Vulnerability Scoring System (CVSS), kemudian disusun menjadi dataset awal untuk rancangan klasifikasi risiko berbasis Random Forest. Hasil penelitian menunjukkan bahwa Roundcube tetap dapat diakses dan digunakan untuk aktivitas email pada kedua skenario pengujian. Meskipun UFW telah diaktifkan, Nmap masih mendeteksi port FTP, SSH, SMTP, DNS, HTTP, POP3, IMAP, IMAPS, dan POP3S dalam kondisi terbuka. Temuan tersebut menunjukkan bahwa aktivasi firewall belum secara langsung mengurangi eksposur layanan apabila rule yang diterapkan masih terlalu longgar dan belum disesuaikan dengan kebutuhan sistem. Risiko tertinggi ditemukan pada penggunaan HTTP tanpa HTTPS karena webmail memproses kredensial pengguna dan isi komunikasi melalui kanal yang tidak terenkripsi. Sebagian besar temuan lain berada pada kategori risiko sedang karena layanan masih terbatas pada jaringan lokal. Penelitian ini menyimpulkan bahwa keamanan dasar perlu dilanjutkan dengan hardening yang lebih spesifik, meliputi pembatasan rule firewall, penerapan HTTPS, penonaktifan service yang tidak diperlukan, penguatan autentikasi SSH, konfigurasi Fail2Ban, serta pemantauan log secara berkala. Dataset awal yang dihasilkan dapat menjadi dasar pengembangan dan pengujian kuantitatif model Random Forest pada penelitian selanjutnya dengan jumlah sampel yang lebih besar.

Downloads

Download data is not yet available.

References

1. Akhilesh, R., Bills, O., Chilamkurti, N., & Chowdhury, M. J. M. (2022). Automated penetration testing framework for smart-home-based IoT devices. Future Internet, 14(10), Article 276. https://doi.org/10.3390/fi14100276

2. Ashiq, M. I., Fiebig, T., & Chung, T. (2025). Unraveling the complexities of MTA-STS deployment and management in securing email. Proceedings of the ACM Internet Measurement Conference. https://doi.org/10.1145/3730567.3732916

3. Bartoli, A. (2023). Network architecture and ROA protection of government mail domains: A case study. Computer Communications. https://doi.org/10.1016/j.comcom.2023.02.004

4. Bhandari, G. P., Naseer, A., & Moonen, L. (2021). CVEfixes: Automated collection of vulnerabilities and their fixes from open-source software. Proceedings of the International Conference on Predictive Models and Data Analytics in Software Engineering. https://doi.org/10.1145/3475960.3475985

5. Cheimonidis, P., & Rantos, K. (2023). Dynamic risk assessment in cybersecurity: A systematic literature review. Future Internet, 15(10), Article 324. https://doi.org/10.3390/fi15100324

6. Costa, J. C., Roxo, T., Sequeiros, J. B. F., Proenca, H., & Inacio, P. R. M. (2022). Predicting CVSS metric via description interpretation. IEEE Access. https://doi.org/10.1109/ACCESS.2022.3179692

7. Czybik, S., Horlboge, M., & Rieck, K. (2023). Lazy gatekeepers: A large-scale study on SPF configuration in the wild. Proceedings of the ACM Internet Measurement Conference. https://doi.org/10.1145/3618257.3624827

8. Echeverría, A. D., Cevallos, C., Ortiz-Garcés, I., & Andrade, R. (2021). Cybersecurity model based on hardening for secure Internet of Things implementation. Applied Sciences, 11(7), Article 3260. https://doi.org/10.3390/app11073260

9. Elder, S., Rahman, M. R., Fringer, G., Kapoor, K., & Williams, L. (2024). A survey on software vulnerability exploitability assessment. ACM Computing Surveys. https://doi.org/10.1145/3648610

10. Fu, M. C., Tantithamthavorn, C., Le, T., Kume, Y., Nguyen, V., Phung, D., & Grundy, J. (2023). AIBugHunter: A practical tool for predicting, classifying and repairing software vulnerabilities. Empirical Software Engineering. https://doi.org/10.1007/s10664-023-10346-3

11. Howland, H. (2021). CVSS: Ubiquitous and broken. Communications of the ACM. https://doi.org/10.1145/3491263

12. Kuppa, A., Aouad, L. M., & Le-Khac, N.-A. (2021). Linking CVE’s to MITRE ATT&CK techniques. Proceedings of the International Conference on Cyber Situational Awareness, Data Analytics and Assessment. https://doi.org/10.1145/3465481.3465758

13. Lee, H., Ashiq, M. I., Muller, M., van Rijswijk-Deij, R., Kwon, T., & Chung, T. (2022). Under the hood of DANE mismanagement in SMTP. Zenodo. https://doi.org/10.5281/zenodo.7696293

14. Li, R., Zhang, Z., Shao, J., Lu, R., Jia, X., & Wei, G. (2023). The potential harm of email delivery: Investigating the HTTPS configurations of webmail services. IEEE Transactions on Dependable and Secure Computing. https://doi.org/10.1109/TDSC.2023.3246600

15. Liu, E., Akiwate, G., Jonker, M., Mirian, A., Savage, S., & Voelker, G. M. (2021). Who’s got your mail? Proceedings of the ACM Internet Measurement Conference. https://doi.org/10.1145/3487552.3487820

16. Sarker, K. U., Yunus, F., & Deraman, A. (2023). Penetration taxonomy: A systematic review on the penetration process, framework, standards, tools, and scoring methods. Sustainability, 15(13), Article 10471. https://doi.org/10.3390/su151310471

17. Seara, J. P., & Serrão, C. (2024). Automation of system security vulnerabilities detection using open-source software. Electronics, 13(5), Article 873. https://doi.org/10.3390/electronics13050873

18. Silvestri, S., Islam, S., Papastergiou, S., Tzagkarakis, C., & Ciampi, M. (2023). A machine learning approach for the NLP-based analysis of cyber threats and vulnerabilities of the healthcare ecosystem. Sensors, 23(2), Article 651. https://doi.org/10.3390/s23020651

19. Sotiropoulos, P., Mathas, C.-M., Vassilakis, C., & Kolokotronis, N. (2023). A software vulnerability management framework for the minimization of system attack surface and risk. Electronics, 12(10), Article 2278. https://doi.org/10.3390/electronics12102278

20. Sun, N., Ding, M., Jiang, J., Xu, W., Mo, X., Tai, Y., & Zhang, J. (2023). Cyber threat intelligence mining for proactive cybersecurity defense: A survey and new perspectives. IEEE Communications Surveys & Tutorials. https://doi.org/10.1109/COMST.2023.3273282

21. Tang, K., Tu, C., Mak, S. L. A., & Chau, S. Y. (2025). A multifaceted study on the use of TLS and auto-detect in email ecosystems. Proceedings of the Network and Distributed System Security Symposium. https://doi.org/10.14722/ndss.2025.240532

22. Tatang, D., Flume, R., & Holz, T. (2021). Extended abstract: A first large-scale analysis on usage of MTA-STS. Lecture Notes in Computer Science. https://doi.org/10.1007/978-3-030-80825-9_18

23. Tudosi, A.-D., Graur, A., Balan, D., & Potorac, A. D. (2023). Research on security weakness using penetration testing in a distributed firewall. Sensors, 23(5), Article 2683. https://doi.org/10.3390/s23052683

24. Walkowski, M., Oko, J., & Sujecki, S. (2021). Vulnerability management models using a common vulnerability scoring system. Applied Sciences, 11(18), Article 8735. https://doi.org/10.3390/app11188735

25. Yajima, M., Chiba, D., Yoneya, Y., & Mori, T. (2023). A first look at brand indicators for message identification (BIMI). Lecture Notes in Computer Science. https://doi.org/10.1007/978-3-031-28486-1_20

Downloads

Published

29-07-2026

How to Cite

[1]
E. Manurung, C. Sigiro, and L. M. Sinaga, “Analisis Risiko Roundcube Debian dengan CVSS dan Random Forest”, RIGGS, vol. 5, no. 2, pp. 20667–20677, Jul. 2026.

Issue

Section

Articles