Penerapan Web Application Firewall Berbasis Mod Security untuk Mengatasi Server Side Request Forgery (SSRF)
DOI:
https://doi.org/10.31004/riggs.v5i2.12015Keywords:
Web Application Firewall, Mod Security, OWASP CRS, SSRF, Open Redirect, Insecure Design, Owasp Top 10Abstract
Keamanan aplikasi web menjadi aspek krusial di tengah meningkatnya ancaman siber, khususnya terhadap kerentanan logika bisnis seperti Server-Side Request Forgery (SSRF) dan Open Redirect. Penelitian ini bertujuan untuk menganalisis efektivitas Web Application Firewall (WAF) Mod Security dengan aturan OWASP Core Rule Set (CRS) dalam memitigasi kerentanan tersebut pada sebuah aplikasi web target. Metodologi yang digunakan dalam penelitian ini adalah metode eksperimen yang diintegrasikan dengan kerangka kerja Network Development Life Cycle (NDLC). Metodologi NDLC adalah kerangka kerja yang digunakan untuk merancang, membangun, dan mengelola infrastruktur jaringan atau keamanan secara terstruktur. Hasil pengujian tahap awal menunjukkan bahwa mode blocking dengan aturan standar efektif menggagalkan serangan dengan merespon status HTTP 403 Forbidden. Namun, konfigurasi standar ini memicu insiden False Positive, di mana permintaan valid yang memuat alamat IP internal pada fitur Check Stock turut terblokir, sehingga mengganggu ketersediaan layanan (availability). Untuk mengatasi hal tersebut, dilakukan penyesuaian aturan (Rule Tuning) melalui mekanisme whitelisting berbasis Regular Expression (Regex) yang divalidasi secara ketat. Hasil verifikasi akhir menunjukkan bahwa implementasi aturan custom berhasil memulihkan akses untuk permintaan yang sah (HTTP 200 OK) sekaligus tetap memblokir upaya eksploitasi dan manipulasi parameter. Penelitian ini menyimpulkan bahwa implementasi Mod Security dengan kombinasi OWASP CRS dan Custom Rules mampu melindungi aplikasi pada server dari serangan SSRF secara efektif, menjaga fungsionalitas katalog tetap berjalan normal, serta memungkinkan administrator memantau lalu lintas data yang mencurigakan.
Downloads
References
[1] E. Wang et al., “Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications.” [Online]. Available: https://github.com/SSRFuzz/SSRFuzz
[2] B. Zhang, C. Lou, Y. Lou, R. Ren, and Q. Wang, “SSRFinder: SSRF vulnerability detection and validation based on program dependency graphs and pre-trained models,” Expert Syst. Appl., vol. 326, p. 132725, Sep. 2026, doi: 10.1016/J.ESWA.2026.132725.
[3] A. Abibulaiev, P. Pukach, and M. Vovk, “Context-Aware ML/NLP Pipeline for Real-Time Anomaly Detection and Risk Assessment in Cloud API Traffic,” Mach. Learn. Knowl. Extr., vol. 8, no. 1, p. 25, Jan. 2026, doi: 10.3390/make8010025.
[4] Z. Qiu, S. Shao, Q. Zhao, and G. Jin, “Understanding and detecting server-side request races in web applications,” in Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, New York, NY, USA: ACM, Aug. 2021, pp. 842–854. doi: 10.1145/3468264.3468594.
[5] N. Arora, P. Singh, S. Sahu, V. K. Keshari, and M. Vinoth Kumar, “Preventing SSRF (Server-Side Request Forgery) and CSRF (Cross-Site Request Forgery) Using Extended Visual Cryptography and QR Code,” 2021, pp. 215–227. doi: 10.1007/978-981-15-6707-0_20.
[6] B. Jabiyev, O. Mirzaei, A. Kharraz, and E. Kirda, “Preventing server-side request forgery attacks,” Proceedings of the ACM Symposium on Applied Computing, pp. 1626–1635, 2021, doi: 10.1145/3412841.3442036.
[7] Y. Ji, T. Dai, Z. Zhou, Y. Tang, and J. He, “Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint Analysis,” Proceedings of the ACM on Programming Languages, vol. 9, no. 1, Apr. 2025, doi: 10.1145/3720488.
[8] F. Fachri, “OPTIMASI KEAMANAN WEB SERVER TERHADAP SERANGAN BRUTE-FORCE MENGGUNAKAN PENETRATION TESTING,” vol. 10, no. 1, pp. 51–58, 2023, doi: 10.25126/jtiik.2023105872.
[9] Y. Zhou, E. Wang, and S. Ma, “SSRFSeek: An LLM-based Static Analysis Framework for Detecting SSRF Vulnerabilities in PHP Applications,” in 2025 IEEE 6th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT), IEEE, Apr. 2025, pp. 939–944. doi: 10.1109/AINIT65432.2025.11035424.
[10] B. Dawadi, B. Adhikari, and D. Srivastava, “Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks,” Sensors, vol. 23, no. 4, p. 2073, Feb. 2023, doi: 10.3390/s23042073.
[11] A. Thakkar and R. Lohiya, “A Review on Machine Learning and Deep Learning Perspectives of IDS for IoT: Recent Updates, Security Issues, and Challenges,” Archives of Computational Methods in Engineering, vol. 28, no. 4, pp. 3211–3243, Jun. 2021, doi: 10.1007/s11831-020-09496-0.
[12] M. R. Fazli, “ANALISIS KERENTANAN INSECURE DESIGN DAN SERVER SIDE REQUEST FORGERY (SSRF) DENGAN METODE PTES (STUDI KASUS OBJEK BUGGY WEB APPLICATION).”
[13] J. Mukamisha, A. Iradukunda, E. Manzi, and J. D. Ndibwile, “Mitigating Server-Side Request Forgery (SSRF) Attacks: An Empirical Analysis of Deep Learning-Based Approaches,” in Proceedings - 2025 9th International Conference on Cryptography, Security and Privacy, CSP 2025, 2025. doi: 10.1109/CSP66295.2025.00027.
[14] K. Al-Talak and O. Abbass, “Detecting Server-Side Request Forgery (SSRF) Attack by using Deep Learning Techniques.” [Online]. Available: www.ijacsa.thesai.org
[15] F. Naim, Rd. R. Saedudin, and S. K. Y. U. Hediyanto, “ANALYSIS OF WIRELESS AND CABLE NETWORK QUALITY-OF SERVICE PERFORMANCE AT TELKOM UNIVERSITY LANDMARK TOWER USING NETWORK DEVELOPMENT LIFE CYCLE (NDLC) METHOD ,” JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika) , vol. 7, no. 4, Dec. 2022.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Lalu Amirulloh Taufikurrahman, I Putu Hariyadi, Ondi Asroni

This work is licensed under a Creative Commons Attribution 4.0 International License.


















