logo icods

Security Assessment of the Padak Village Administration and Letter Service Information System Using STRIDE, OWASP ZAP, OWASP Top 10 (2021), and the OWASP Risk Rating Methodology

Authors

  • Sophia

    Institut Shanti Bhuana
    Author
  • Yuliana

    Institut Shanti Bhuana
    Author
  • Santi Thomas

    Institut Shanti Bhuana
    Author
  • Devon Surya Pranata

    Institut Shanti Bhuana
    Author

DOI:

https://doi.org/10.62201/xg8zmd31

Keywords:

OWASP Top 10, OWASP ZAP, Risk Assessment, STRIDE, Web Application Security

Abstract

The Padak Village Administration and Letter Service Information System is a web-based application that supports administrative services for citizens, making security evaluation essential to identify threats, vulnerabilities, and risk levels that may affect system security. This study aims to identify security threats, discover vulnerabilities, determine risk levels, and propose mitigation recommendations to improve system security. A descriptive approach was employed by integrating the STRIDE method for threat identification, OWASP ZAP (AJAX Spider and Active Scan) for vulnerability assessment, OWASP Top 10 (2021) for vulnerability classification, and the OWASP Risk Rating Methodology for risk assessment based on Likelihood and Impact factors. OWASP ZAP identified 28 security alerts during the scanning process. However, only 21 vulnerabilities were included in the risk assessment because the remaining 7 findings were classified as Informational, which only describe application configuration and characteristics without representing directly exploitable security vulnerabilities. The STRIDE analysis identified four categories of security threats, namely Spoofing, Tampering, Repudiation, and Information Disclosure. Furthermore, the 21 selected vulnerabilities were mapped into six OWASP Top 10 (2021) categories: A01:2021 Broken Access Control, A02:2021 Cryptographic Failures, A03:2021 Injection, A05:2021 Security Misconfiguration, A07:2021 Identification and Authentication Failures, and A08:2021 Software and Data Integrity Failures. Based on the OWASP Risk Rating Methodology, the assessment identified 2 Critical, 15 High, 3 Medium, and 1 Low-risk vulnerabilities. The study proposes mitigation recommendations, including the implementation of Prepared Statements, Anti-CSRF Tokens, Content Security Policy (CSP), HTTP Security Headers, HTTPS, Subresource Integrity (SRI), strengthened Cross-Origin Resource Sharing (CORS) configuration, secure Cookie attributes, and application security hardening in accordance with OWASP ZAP recommendations.

Downloads

Published

2026-09-07