Purba, Jonathan (2026) Perancangan Dan Implementasi Security Service Edge Berbasis Zero Trust Network Access, Secure Web Gateway, Dan Cloud Access Security Broker Pada Layanan Private Cloud Storage. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5025221132-Jonathan Purba-Buku.pdf - Accepted Version Restricted to Repository staff only Download (9MB) | Request a copy |
Abstract
Layanan Private Cloud Storage merupakan solusi penyimpanan data yang memberikan kedaulatan penuh bagi organisasi, namun metode akses jarak jauh tradisional seperti Virtual Private Network (VPN) seringkali memiliki keterbatasan dalam skalabilitas, latensi, dan celah keamanan pada jaringan datar. Selain itu, organisasi menghadapi ancaman Shadow IT dan kebocoran data akibat kurangnya visibilitas terhadap lalu lintas pengguna. Penelitian ini bertujuan untuk merancang dan mengimplementasikan arsitektur Security Service Edge (SSE) berbasis Cloudflare Zero Trust untuk mengamankan layanan Private Cloud (Nextcloud). Sistem ini mengintegrasikan Zero Trust Network Access (ZTNA) untuk autentikasi berbasis identitas dan postur perangkat, Secure Web Gateway (SWG) untuk memfilter ancaman siber, serta Cloud Access Security Broker (CASB) terintegrasi Data Loss Prevention (DLP) untuk membatasi penggunaan aplikasi penyimpanan tidak terotorisasi. Hasil pengujian menunjukkan bahwa arsitektur SSE yang dikonfigurasi melalui pendekatan Infrastructure as Code (IaC) mampu mengamankan akses jarak jauh tanpa mengekspos port publik, memitigasi risiko Shadow IT, serta mencegah eksfiltrasi data sensitif secara efektif.
===============================================================================================================================
Private Cloud Storage services offer data sovereignty and flexibility for organizations; however, traditional remote access methods, such as Virtual Private Networks (VPN), often suffer from limitations regarding scalability, high latency, and security vulnerabilities associated with flat networks. Furthermore, organizations face significant threats from Shadow IT and potential data loss due to a lack of visibility into user traffic. This study aims to design and implement a Security Service Edge (SSE) architecture utilizing Cloudflare Zero Trust to secure Private Cloud services (Nextcloud). The proposed system integrates Zero Trust Network Access (ZTNA) for identity- and device posture-based authentication, a Secure Web Gateway (SWG) to filter cyber threats, and a Cloud Access Security Broker (CASB) integrated with Data Loss Prevention (DLP) to restrict the use of unsanctioned storage applications. The testing results demonstrate that the SSE architecture, configured through an Infrastructure as Code (IaC) approach, effectively secures remote access without exposing public inbound ports, mitigates Shadow IT risks, and prevents sensitive data exfiltration.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | Security Service Edge (SSE), Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Private Cloud Storage, Infrastructure as Code |
| Subjects: | T Technology > T Technology (General) > T58.5 Information technology. IT--Auditing |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis |
| Depositing User: | Jonathan Purba |
| Date Deposited: | 28 Jul 2026 08:05 |
| Last Modified: | 28 Jul 2026 08:05 |
| URI: | http://repository.its.ac.id/id/eprint/137743 |
Actions (login required)
![]() |
View Item |
