Trusted Hardware, Untrusted Operators: An Insider-Enabled Threat Taxonomy for National Computer-Based Testing Infrastructure
Perangkat Keras Terpercaya, Operator Tak Terpercaya: Taksonomi Ancaman Berbasis Orang-Dalam untuk Infrastruktur Ujian Nasional Berbasis Komputer
DOI:
https://doi.org/10.57152/ijeere.v6i1.3148Keywords:
Ancaman Orang-Dalam, Ujian Berbasis Komputer, Pemodelan Ancaman, Infrastruktur Informasi Kritis, STRIDEAbstract
The security literature on computer-based testing (CBT) has developed almost entirely around remote proctoring, where the threat model assumes untrusted examinee-owned hardware operating in an uncontrolled environment. This framing treats institution-controlled hardware under physical invigilation as a secure baseline. We argue this assumption is unsound, substantiating the argument with evidence from Indonesia's national university entrance examination (UTBK-SNBT), a high-stakes CBT administered to 871,496 registered candidates in 2026 (846,518 present) across a distributed network of state-university testing centres. Drawing on publicly documented incidents from the 2025 and 2026 administrations, we reconstruct two organised attacks in which institution-controlled examination hardware was compromised despite physical proctors, metal detectors, and closed-circuit surveillance. In the first, campus IT staff with legitimate administrative privileges installed remote-access software on examination workstations; nine suspects were charged under Articles 30 and 32 of the Electronic Information and Transactions Law. In the second, a covert proxy appliance comprising two mini PCs, a router, and an uninterruptible power supply was concealed within a printer carton approximately six months before the examination. From these incidents we derive a five-class threat taxonomy and construct a STRIDE-based threat model mapped to MITRE ATT&CK. We show that the only control demonstrably effective against the most sophisticated attack was network-layer anomaly detection, whereas the perimeter controls emphasised in policy discourse failed by design. We conclude that trusted-hardware CBT constitutes a distinct, under-theorised threat model, and we outline a research agenda for its systematic study.
References
P. SNPMB, “Siaran Pers No. 02/SIPERS/SNPMB/V/2026 tentang Pengumuman Hasil SNBT 2026,” Sistem Nasional Penerimaan Mahasiswa Baru (SNPMB), 2026. [Online]. Available: https://files.snpmb.id/web2026/02_Sipers%20Pengumuman%20SNBT%202026.pdf
B. Burgess, A. Ginsberg, E. W. Felten, and S. Cohney, “Watching the Watchers: Bias and Vulnerability in Remote Proctoring Software,” arXiv, 2022. doi: 10.48550/arXiv.2205.03009.
R. H. (II.), MITRENET: A Testbed Local Area Network at DTNSRDC. Ft. Belvoir Defense Technical Information Center: Defense Technical Information Center, 1986.
D. G. Balash, D. Kim, D. Shaibekova, R. A. Fainchtein, M. Sherr, and A. J. Aviv, “Examining the Examiners: Students’ Privacy and Security Perceptions of Online Proctoring Services,” in Proceedings of the Seventeenth USENIX Symposium on Usable Privacy and Security (SOUPS), USENIX Association, 2021.
T. Langenfeld, “Internet-Based Proctored Assessment: Security and Fairness Issues,” Educational Measurement: Issues and Practice, vol. 39, no. 3, pp. 24–27, 2020, doi: 10.1111/emip.12359.
S. Cohney et al., “Virtual Classrooms and Real Harms,” in Proceedings of the Seventeenth USENIX Symposium on Usable Privacy and Security (SOUPS), USENIX Association, 2021.
L. Slusky, “Cybersecurity of Online Proctoring Systems,” Journal of International Technology and Information Management, vol. 29, no. 1, pp. 56–83, 2020, doi: 10.58729/1941-6679.1421.
B. Erdem and M. Karabatak, “Cheating Detection in Online Exams Using Deep Learning and Machine Learning,” Applied Sciences, vol. 15, no. 1, p. 400, 2025, doi: 10.3390/app15010400.
M. N. Ardiansyah, F. Z. Suryahadi, H. E. S. Pratama, and A. P. Sari, “Sistem Deteksi Gerakan Kecurangan UTBK Real-Time dengan YOLOv8 dan Optical Flow,” JISKA (Jurnal Informatika Sunan Kalijaga), vol. 11, no. 1, pp. 83–97, 2026, doi: 10.14421/jiska.5365.
F. Bimantoro, I. G. P. S. Wijaya, and M. R. Aohana, “Pendeteksian Kecurangan Ujian melalui CCTV Menggunakan Algoritma YOLOv5,” in Seminar Nasional Teknologi & Sains, 2024, pp. 109–117.
A. Righo and S. B. Saragih, “Analisis Efektifitas Penggunaan CBT Exam Browser Berbasis Keamanan Digital (Anti AI) untuk Mencegah Kecurangan Ujian UTS/UAS pada Mata Kuliah Manajemen Layanan Kesehatan,” Journal of Innovative and Creativity, vol. 5, no. 2, pp. 11362–11371, 2025, doi: 10.31004/joecy.v5i2.2790.
F. N. Iman and I. Farida, “Pengembangan Aplikasi CBT Menggunakan Framework Laravel dan Electron JS,” JIKA (Jurnal Informatika), vol. 9, no. 4, pp. 2713–2722, 2025, doi: 10.31000/jika.v9i4.14795.
R. K. Yin, Case Study Research and Applications: Design and Methods, 6th ed. Thousand Oaks, CA: SAGE Publications, 2018.
R. of Indonesia, Law No. 11 of 2008 concerning Electronic Information and Transactions, as amended by Law No. 19 of 2016 and Law No. 1 of 2024. Government of the Republic of Indonesia, 2008.
R. of Indonesia, Law No. 27 of 2022 concerning Personal Data Protection. Government of the Republic of Indonesia, 2022.
R. of Indonesia, Law No. 12 of 2012 concerning Higher Education. Government of the Republic of Indonesia, 2012.
A. Shostack, Threat Modeling: Designing for Security. Indianapolis, IN: Wiley, 2014.
B. Schneier, “Attack Trees,” Dr. Dobb’s Journal, vol. 24, no. 12, pp. 21–29, 1999.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Mulkan Fadhli

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.













