ResearcherCollabResearcherCollab
Sign inJoin free →
Ahmad Heryanto

Ahmad Heryanto

Computer Science
Universitas Sriwijaya · Indonesia
Connect →
10
Publications
0
Collaborations
0
Active calls

About

I am a faculty member in the Computer Engineering Study Program at Universitas Sriwijaya (UNSRI), specializing in computer networks, operating systems, cybersecurity, distributed systems, and parallel computing. I have held several leadership positions, including Head of the Training and Certification Center at the Faculty of Computer Science (2014–2015), Head of the Computer Networking Laboratory (2015–2023), Head of the Computer Engineering Study Program (2023–2025), and Head of Subdivision at the Directorate of Information Technology Services and Development (DPPTI) since 2025. My professional experience encompasses academic program management, curriculum development, network and data center infrastructure, information systems, and institutional cybersecurity. My research interests include intrusion detection, cyberattack mitigation using machine learning and deep learning, and performance optimization in distributed and parallel computing environments.

Research keywords

Computer Networks and Network ArchitectureNetwork and System SecurityIntrusion DetectionCyber Attack MitigationOperating Systems and Linux-Based Server ManagementDistributed Systems and Cloud ComputingParallel Computing and High-Performance Computing (HPC)Network Traffic Analysis and Anomaly DetectionMachine Learning and Deep Learning for CybersecuritySecure and Scalable IT Infrastructure

Publications

10

Security and Performance Evaluation of PPTP-Based VPN with AES Encryption in Enterprise Network Environments

Jurnal Teknik Informatika (Jutif) · 2025

In the context of the current digital era, Virtual Private Networks (VPNs) serve a critical function in ensuring the confidentiality and integrity of data transmitted across public networks, particularly within corporate environments. This study presents a comprehensive analysis of VPN security and performance, with a specific focus on the Point-to-Point Tunneling Protocol (PPTP) and the implementation of encryption algorithms such as AES-128 and AES-256. Despite the widespread adoption of PPTP due to its simplicity and broad compatibility, it exhibits significant security vulnerabilities, primarily stemming from its reliance on the outdated RC4-based Microsoft Point-to-Point Encryption (MPPE) and the susceptible MS-CHAP authentication protocol, which is highly vulnerable to brute-force and dictionary attacks. Empirical findings indicate that, although AES-128 and AES-256 introduce minor performance trade-offs compared to unencrypted configurations, AES-256 demonstrates markedly enhanced security, achieving a 98.9% authentication success rate and a threat detection time of 122 milliseconds. Nevertheless, increased user load adversely impacts network performance, with throughput declining from 95 Mbps to 40 Mbps as the user count rises from 5 to 50, accompanied by elevated latency and packet loss. Comparative analysis across three encryption scenarios AES-128, AES-256, and MPPE-PPTP reveals a consistent degradation in network performance as user load increases, with AES-256 offering the strongest security at the cost of slightly reduced throughput and increased latency under high-load conditions. MPPE-PPTP, while providing better throughput, lacks adequate security, making it unsuitable for high-risk environments. Based on these observations, this study recommends the implementation of AES-256 encryption in enterprise networks requiring high security, supported by continuous performance monitoring and strategic capacity planning. Furthermore, the adoption of a secure site-to-site VPN architecture is proposed to facilitate reliable and secure communication between geographically distributed office locations.

Early-Stage Detection of ICMPv6 Flooding Using Decision Trees in Smart Home Systems (Work in Progress)

2025

The ICMPv6 "Packet Too Big" flooding attack is a significant threat to IPv6 network security, particularly when exploiting vulnerabilities in the automatic address configuration mechanism based on EUI-64 and the Privacy Extension feature. In this scenario, the attacker uses a fixed source address to send a large volume of malicious ICMPv6 packets to various destination addresses derived from the same address structure. This technique takes advantage of weaknesses in the handling of "Packet Too Big" messages and the deterministic nature of the EUI-64 format, potentially causing the target system to become overwhelmed and suffer from degraded network performance. This study utilizes a simulated dataset based on the described scenario to detect the attack using the decision tree algorithm. The evaluation results demonstrate that the algorithm effectively identifies attack patterns, achieving a test accuracy of 92.37%, with a precision of 100% for the Normal class and 86.76% for the Flood class. The recall for the Normal class is 84.73%, while the Flood class reaches 100%. The F1-score is 91.73% for the Normal class and 92.93% for the Flood class, indicating the model's strong ability to balance precision and recall across both classes.

Comparative Analysis of Decision Tree, Random Forest, and XGBoost for IoT Intrusion Detection in Smart Home

2025

The proliferation of Internet of Things (IoT) devices in smart home environments has introduced significant cybersecurity challenges stemming from increased network complexity and vulnerability to attacks. This study conducts a comparative analysis of three machine learning techniques: Decision Tree (DT), Random Forest (RF), and Extreme Gradient Boosting (XGBoost) for intrusion detection in smart home networks. To address the issue of class imbalance in cybersecurity datasets, advanced preprocessing steps were implemented, including feature selection using Mutual Information and Recursive Feature Elimination (RFE), normalization, and the Synthetic Minority Oversampling Technique (SMOTE). The experiments were conducted using the COMNETS Smart Home dataset, which realistically represents both benign and malicious network traffic. The results demonstrate that ensemble methods, particularly XGBoost, achieve an accuracy of 97.2% and a ROC-AUC score of 0.983, thus outperforming conventional Decision Tree models. This study underscores the critical role of robust data preprocessing and hyperparameter optimization in enhancing the performance of lightweight security models for future smart home development.

Enhancing Security against Outsider SSH Lateral Movement through Rule-Based Detection

2025

The rapid advancement of computer network technology, while having a positive impact on data exchange and communication, has simultaneously given rise to the risk of cyber attacks, one of which is lateral movement. This attack occurs when an attacker gains initial access to a system and then maneuvers to other systems within the internal network to obtain information or expand control. The findings of this study indicate that attacks from external parties (outsider attackers) successfully gained access to the victim's system, and these activities were successfully detected using network analysis tools such as Wireshark, Snort, and NetworkMiner. Collectively, these three tools demonstrated effectiveness in identifying attack patterns based on data packet analysis, predefined warning rules, and network traffic monitoring. Our mitigation efforts also proved to be effective. Follow-Up testing confirmed that the implemented security changes specifically, altering the SSH port and mandating key-based authentication over passwords were successful in preventing a recurrence of the attack. The key takeaway is that a system's defense against SSH-based threats is greatly improved when a rule-based detection approach is supported by proper security hardening.

Optimizing Web Server Performance: A Comparative Analysis of Central Manager and Round Robin Load Balancing Algorithms

2024

Central manager algorithm has a lower average throughput compared to the round robin algorithm. This is evidenced by a significant decrease in throughput values during measurements. Central manager algorithm provides a faster average response time than round robin algorithm, despite experiencing an increase in response time values over time. Central manager algorithm shows a higher request loss rate and many requests are not served. Under normal performance conditions, both algorithms yield the same average request loss rate, achieving stable values without failed requests. The central manager algorithm ensures relatively balanced resource availability, including CPU and memory usage, across each slave web server compared to the round robin algorithm. The results show that increasing the number of clients and client requests during system testing to better observe server resource availability and load distribution performance. For future research, it is recommended to increase the number of clients in the system testing to enhance server load and to introduce client request actions on the web server to further highlight resource availability on each web server.

A Novel Framework for Enhancing User Experience in Virtual Reality Environments

International Journal of Computer Engineering in Research Trends · 2023

The International Journal of Computer Engineering in Research Trends (IJCERT) is a peer-reviewed, open access journal that publishes high-quality research papers, reviews, short communications, and notes in the field of computer science engineering and its research trends. The journal covers a wide range of topics in computer science and engineering, including: Welcome to the International Journal of Computer Engineering in Research Trends (IJCERT), is a peer-reviewed, open access journal dedicated to publishing innovative research papers, reviews, short communications, and notes in the field of computer science engineering and related disciplines. IJCERT encourages conceptual, state-of-the-art, research, standard, implementation, experimental, application, and industrial case study discussions in various areas, including: computer architecture, computer networks, software engineering, information security, artificial intelligence, machine learning, data science, robotics, cyber-physical systems, the internet of things, and other areas of computer science engineering and Its Applications.

An Improved LSTM-PCA Ensemble Classifier for SQL Injection and XSS Attack Detection

Computer Systems Science and Engineering · 2023

The Repository Mahasiswa (RAMA) is a national repository of research reports in the form of final assignments, student projects, theses, dissertations, and research reports of lecturers or researchers that have not yet been published in journals, conferences, or integrated books from the scientific repository of universities and research institutes in Indonesia. The increasing popularity of the RAMA Repository leads to security issues, including the two most widespread, vulnerable attacks i.e., Structured Query Language (SQL) injection and cross-site scripting (XSS) attacks. An attacker gaining access to data and performing unauthorized data modifications is extremely dangerous. This paper aims to provide an attack detection system for securing the repository portal from the abovementioned attacks. The proposed system combines a Long Short–Term Memory and Principal Component Analysis (LSTM-PCA) model as a classifier. This model can effectively solve the vanishing gradient problem caused by excessive positive samples. The experiment results show that the proposed system achieves an accuracy of 96.85% using an 80%:20% ratio of training data and testing data. The rationale for this best achievement is that the LSTM’s Forget Gate works very well as the PCA supplies only selected features that are significantly relevant to the attacks’ patterns. The Forget Gate in LSTM is responsible for deciding which information should be kept for computing the cell state and which one is not relevant and can be discarded. In addition, the LSTM’s Input Gate assists in finding out crucial information and stores specific relevant data in the memory.

Behavior Pattern Recognition of Game Dragon Nest Using Bloom Filter Method

International Journal of Communication Networks and Information Security (IJCNIS) · 2022

Dragon Nest is one of Massively Multiplayer Online Role-playing Game (MMORPG online games. It has become the most popular online game played by people around the world. This work observes two examples of the MMORPG online games: the Dragon Nest INA and the Legend DN II. The purpose is to analyze the traffic data of the Dragon Nest to find and discern the patterns of behavior of the Dragon Nest INA and the Legend DN II using Deep Packet Inspection (DPI). A dataset is constructed by capturing traffic data from the testbed environment. Then feature extraction, feature selection, and visualization are performed during the experiments. Experiment results shows the traffic data of the Dragon Nest INA is higher than the Legend DN II. It is because of the difference in the number of entries in the game. Then, the Bloom filter method is used as a tool to check the existence of a pattern of the Dragon Nest in the dataset. The false positive rate of matching is 0.399576%.

Cyberattack Feature Selection using Correlation-Based Feature Selection Method in an Intrusion Detection System

2022

An intrusion detection system (IDS) is software or hardware that works as a monitoring and defense system against cyberattacks. This system monitors computer systems or network activities that have the potential to violate security policies. In general, there are two techniques used by an IDS in its cyberattack detection system: signature-based and anomaly-based. However, these techniques still face some problems, such as false alarm warnings, low accuracy and precision rates, high-dimensional data, complex data structures, and long computational times. IDS performance can be improved by implementing feature selection, which can reduce the amount of data to be processed on the IDS detection engine. This research used correlation-based feature selection (CFS). Experimental results on CIC-IDS2018 dataset show optimal IDS performance. The proposed CFS-based IDS achieves an accuracy of 99.9995%, recall of 100%, specificity of 99.9985%, precision of 99.9992, F1-score of 99.9996%, true positive rate of 99.9992%, and true negative rate of 100%.

Ransomware Detection Based On Opcode Behavior Using K-Nearest Neighbors Algorithm

Information Technology And Control · 2021

Ransomware is a malware that represents a serious threat to a user’s information privacy. By investigating howransomware works, we may be able to recognise its atomic behaviour. In return, we will be able to detect theransomware at an earlier stage with better accuracy. In this paper, we propose Control Flow Graph (CFG) asan extracting opcode behaviour technique, combined with 4-gram (sequence of 4 “words”) to extract opcodesequence to be incorporated into Trojan Ransomware detection method using K-Nearest Neighbors (K-NN)algorithm. The opcode CFG 4-gram can fully represent the detailed behavioural characteristics of Trojan Ransomware.The proposed ransomware detection method considers the closest distance to a previously identifiedransomware pattern. Experimental results show that the proposed technique using K-NN, obtains the best accuracyof 98.86% for 1-gram opcode and using 1-NN classifier.

Other Computer Science researchers

RM
Ritaban Mitra
University at Buffalo SUNY · United States
RM
Raymond Mbam
Independent Researcher · United States
JS
Jane Smith
Independent Researcher · Germany
JM
Jyotir Moy Chatterjee
Graphic Era University · India
DK
Dipanwita Kundu
Independent Researcher · India
Swapnil Rajput
Swapnil Rajput
Dayalbagh Educational Institute · India
ResearcherCollab
Want to collaborate with Ahmad?
Connect with researchers worldwide. Free to join.
Join ResearcherCollab →