Analisis Literatur Sistematis Pengujian Keamanan Website Layanan Keimigrasian dengan Metode Black Box dan White Box Menggunakan Pedoman PRISMA
DOI:
https://doi.org/10.61132/maeswara.v4i4.2752Keywords:
Black Box, Immigration Services, Penetration Testing, Website Security, White BoxAbstract
The digital transformation of immigration services requires websites that are secure, reliable, and capable of protecting sensitive user data. At the same time, the increasing use of websites in public services amplifies the risk of exploiting application security vulnerabilities. This study aims to systematically analyse prior studies on website security testing using black box and white box approaches and to examine the tendency of their effectiveness in the context of immigration service websites. The method used is a Systematic Literature Review (SLR) following the PRISMA 2020 guideline. PRISMA 2020 provides a checklist and flow diagram for transparent systematic review reporting, while the OWASP Web Security Testing Guide (WSTG) serves as a comprehensive guideline for web application security testing. Literature sources were obtained from Garuda, Scopus, Google Scholar, and Semantic Scholar within the 2021-2026 publication period. Based on the identification, screening, and eligibility selection process, 30 articles were selected. The synthesis results show that the black box approach still dominates website security testing because it is more practical, faster, and suitable for simulating attacks from the external side. In contrast, white box provides greater analytical depth because it leverages knowledge of the internal structure of the application. The most dominant tools and references are OWASP ZAP, OWASP Top 10, and OWASP WSTG. This study concludes that for immigration service websites, black box is more effective for initial detection and evaluation from the attacker's perspective, whereas white box is more effective for in-depth verification and continuous improvement. Therefore, the combination of both approaches is the most recommended.
Downloads
References
Adhiguna, M. A., et al. (2023). Pengujian input validation pada aplikasi website.
Althunayyan, M., et al. (2022). Evaluation of black-box web application security scanners in detecting injection vulnerabilities. Electronics, 11(13), 2049. https://doi.org/10.3390/electronics11132049
Armando, Y., & Rosalina. (2023). Penetration testing Tangerang City web application with implementing OWASP Top 10 web security risks framework. JISA (Jurnal Informatika dan Sistem Aplikasi), 6(2). https://doi.org/10.31326/jisa.v6i2.1656
Aydos, M., Aldan, Ç., Coşkun, E., & Soydan, A. (2022). Security testing of web applications: A systematic mapping of the literature. Journal of King Saud University - Computer and Information Sciences. https://doi.org/10.1016/j.jksuci.2021.09.018
Chahal, N. S., et al. (2022). A proactive approach to assess web application security through the integration of security tools in a security orchestration platform. Computers & Security. https://doi.org/10.1016/j.cose.2022.102886
Chandra, A. A., et al. (2024). Penerapan teknik penetration testing terhadap cross-site scripting dalam pengembangan website. Rabit: Jurnal Teknologi dan Sistem Informasi Univrab, 9(2). https://doi.org/10.36341/rabit.v9i2.4822
Halil, M. I., & Mansur. (2026). Analisis dan perbaikan keamanan sistem informasi web berbasis grey-box dan white-box.
Harahap, B., et al. (2021). Penerapan keamanan OWASP pada website Universitas Battuta. Jurnal Informatika dan Teknologi Pendidikan, 1(2). https://doi.org/10.25008/jitp.v1i2.15
Hidayatulloh, S., & Saptadiaji, D. (2021). Penetration testing pada website universitas menggunakan OWASP.
Imtias, M. B., et al. (2025). Comparative analysis of penetration testing frameworks: OWASP, PTES, and NIST SP 800-115 for detecting web application vulnerabilities. Journal of Applied Informatics and Computing, 9(6). https://doi.org/10.30871/jaic.v9i6.9846
Luthfi, A. (2025). White box penetration testing pada authentication system website. Jurnal Ilmiah Informatika, 13(2). https://doi.org/10.33884/jif.v13i02.10660
Mulyanto, Y., et al. (2022). Analisis keamanan website sekolah.
Narezki, F., et al. (2023). Implementasi penetration testing pada sistem informasi Tribrata.
Narhudin, D. E., et al. (2024). Evaluasi keamanan website terhadap SQL injection dan cross-site scripting.
OWASP Foundation. (2025). OWASP Top 10: 2025. OWASP Foundation.
OWASP Foundation. (2026). OWASP Web Security Testing Guide (WSTG). OWASP Foundation.
Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71
Priambodo, D. F., et al. (2023). Penetration testing web berdasarkan OWASP risk rating. Teknika, 12(1). https://doi.org/10.34148/teknika.v12i1.571
Putri, V. R., et al. (2025). Analysis of information system security using OWASP ZAP on a web-based electronic archiving system. Telematika, 22(3). https://doi.org/10.31315/telematika.v22i3.14241
Rafeli, A. I., et al. (2022). Pengujian celah keamanan dengan OWASP WSTG.
Riandhanu, I. O. (2022). Analisis metode OWASP pada keamanan website absensi.
Rohim, A., & Setiyani, L. (2023). Analisis celah keamanan e-learning.
Rohmaniah, D., et al. (2025). Enhancing website security using vulnerability assessment and penetration testing based on OWASP Top Ten. Journal of Applied Informatics and Computing, 9(2). https://doi.org/10.30871/jaic.v9i2.9069
Widyaningrum, B. N., et al. (2024). Analysis of the OWASP V4.2 method in hospital information system security testing. Journal of Technology and Engineering Management, 5(2). https://doi.org/10.59485/jtemp.v5i2.99
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Maeswara : Jurnal Riset Ilmu Manajemen dan Kewirausahaan

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.




