Penerapan Web Application Firewall Berbasis Mod Security untuk Mengatasi Server Side Request Forgery (SSRF)

Authors

  • Lalu Amirulloh Taufikurrahman Universitas Bumigora
  • I Putu Hariyadi Universitas Bumigora
  • Ondi Asroni Universitas Bumigora

DOI:

https://doi.org/10.31004/riggs.v5i2.12015

Keywords:

Web Application Firewall, Mod Security, OWASP CRS, SSRF, Open Redirect, Insecure Design, Owasp Top 10

Abstract

Keamanan aplikasi web menjadi aspek krusial di tengah meningkatnya ancaman siber, khususnya terhadap kerentanan logika bisnis seperti Server-Side Request Forgery (SSRF) dan Open Redirect. Penelitian ini bertujuan untuk menganalisis efektivitas Web Application Firewall (WAF) Mod Security dengan aturan OWASP Core Rule Set (CRS) dalam memitigasi kerentanan tersebut pada sebuah aplikasi web target. Metodologi yang digunakan dalam penelitian ini adalah metode eksperimen yang diintegrasikan dengan kerangka kerja Network Development Life Cycle (NDLC). Metodologi NDLC adalah kerangka kerja yang digunakan untuk merancang, membangun, dan mengelola infrastruktur jaringan atau keamanan secara terstruktur. Hasil pengujian tahap awal menunjukkan bahwa mode blocking dengan aturan standar efektif menggagalkan serangan dengan merespon status HTTP 403 Forbidden. Namun, konfigurasi standar ini memicu insiden False Positive, di mana permintaan valid yang memuat alamat IP internal pada fitur Check Stock turut terblokir, sehingga mengganggu ketersediaan layanan (availability). Untuk mengatasi hal tersebut, dilakukan penyesuaian aturan (Rule Tuning) melalui mekanisme whitelisting berbasis Regular Expression (Regex) yang divalidasi secara ketat. Hasil verifikasi akhir menunjukkan bahwa implementasi aturan custom berhasil memulihkan akses untuk permintaan yang sah (HTTP 200 OK) sekaligus tetap memblokir upaya eksploitasi dan manipulasi parameter. Penelitian ini menyimpulkan bahwa implementasi Mod Security dengan kombinasi OWASP CRS dan Custom Rules mampu melindungi aplikasi pada server dari serangan SSRF secara efektif, menjaga fungsionalitas katalog tetap berjalan normal, serta memungkinkan administrator memantau lalu lintas data yang mencurigakan.

Downloads

Download data is not yet available.

References

[1] E. Wang et al., “Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications.” [Online]. Available: https://github.com/SSRFuzz/SSRFuzz

[2] B. Zhang, C. Lou, Y. Lou, R. Ren, and Q. Wang, “SSRFinder: SSRF vulnerability detection and validation based on program dependency graphs and pre-trained models,” Expert Syst. Appl., vol. 326, p. 132725, Sep. 2026, doi: 10.1016/J.ESWA.2026.132725.

[3] A. Abibulaiev, P. Pukach, and M. Vovk, “Context-Aware ML/NLP Pipeline for Real-Time Anomaly Detection and Risk Assessment in Cloud API Traffic,” Mach. Learn. Knowl. Extr., vol. 8, no. 1, p. 25, Jan. 2026, doi: 10.3390/make8010025.

[4] Z. Qiu, S. Shao, Q. Zhao, and G. Jin, “Understanding and detecting server-side request races in web applications,” in Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, New York, NY, USA: ACM, Aug. 2021, pp. 842–854. doi: 10.1145/3468264.3468594.

[5] N. Arora, P. Singh, S. Sahu, V. K. Keshari, and M. Vinoth Kumar, “Preventing SSRF (Server-Side Request Forgery) and CSRF (Cross-Site Request Forgery) Using Extended Visual Cryptography and QR Code,” 2021, pp. 215–227. doi: 10.1007/978-981-15-6707-0_20.

[6] B. Jabiyev, O. Mirzaei, A. Kharraz, and E. Kirda, “Preventing server-side request forgery attacks,” Proceedings of the ACM Symposium on Applied Computing, pp. 1626–1635, 2021, doi: 10.1145/3412841.3442036.

[7] Y. Ji, T. Dai, Z. Zhou, Y. Tang, and J. He, “Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint Analysis,” Proceedings of the ACM on Programming Languages, vol. 9, no. 1, Apr. 2025, doi: 10.1145/3720488.

[8] F. Fachri, “OPTIMASI KEAMANAN WEB SERVER TERHADAP SERANGAN BRUTE-FORCE MENGGUNAKAN PENETRATION TESTING,” vol. 10, no. 1, pp. 51–58, 2023, doi: 10.25126/jtiik.2023105872.

[9] Y. Zhou, E. Wang, and S. Ma, “SSRFSeek: An LLM-based Static Analysis Framework for Detecting SSRF Vulnerabilities in PHP Applications,” in 2025 IEEE 6th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT), IEEE, Apr. 2025, pp. 939–944. doi: 10.1109/AINIT65432.2025.11035424.

[10] B. Dawadi, B. Adhikari, and D. Srivastava, “Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks,” Sensors, vol. 23, no. 4, p. 2073, Feb. 2023, doi: 10.3390/s23042073.

[11] A. Thakkar and R. Lohiya, “A Review on Machine Learning and Deep Learning Perspectives of IDS for IoT: Recent Updates, Security Issues, and Challenges,” Archives of Computational Methods in Engineering, vol. 28, no. 4, pp. 3211–3243, Jun. 2021, doi: 10.1007/s11831-020-09496-0.

[12] M. R. Fazli, “ANALISIS KERENTANAN INSECURE DESIGN DAN SERVER SIDE REQUEST FORGERY (SSRF) DENGAN METODE PTES (STUDI KASUS OBJEK BUGGY WEB APPLICATION).”

[13] J. Mukamisha, A. Iradukunda, E. Manzi, and J. D. Ndibwile, “Mitigating Server-Side Request Forgery (SSRF) Attacks: An Empirical Analysis of Deep Learning-Based Approaches,” in Proceedings - 2025 9th International Conference on Cryptography, Security and Privacy, CSP 2025, 2025. doi: 10.1109/CSP66295.2025.00027.

[14] K. Al-Talak and O. Abbass, “Detecting Server-Side Request Forgery (SSRF) Attack by using Deep Learning Techniques.” [Online]. Available: www.ijacsa.thesai.org

[15] F. Naim, Rd. R. Saedudin, and S. K. Y. U. Hediyanto, “ANALYSIS OF WIRELESS AND CABLE NETWORK QUALITY-OF SERVICE PERFORMANCE AT TELKOM UNIVERSITY LANDMARK TOWER USING NETWORK DEVELOPMENT LIFE CYCLE (NDLC) METHOD ,” JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika) , vol. 7, no. 4, Dec. 2022.

Downloads

Published

27-07-2026

How to Cite

[1]
L. A. Taufikurrahman, I. P. Hariyadi, and O. Asroni, “Penerapan Web Application Firewall Berbasis Mod Security untuk Mengatasi Server Side Request Forgery (SSRF)”, RIGGS, vol. 5, no. 2, pp. 19671–19677, Jul. 2026.

Issue

Section

Articles