IMPLEMENTASI LOGIC-BASED ROW-LEVEL SECURITY DAN ROLE-BASED ACCESS CONTROL PADA REST API MENGGUNAKAN GOLANG DENGAN PENDEKATAN GRAY-BOX TESTING
| dc.contributor.advisor | Kurniawan, Dwi Ely | |
| dc.contributor.author | Fudail, Zabran | |
| dc.date.accessioned | 2026-08-14T07:51:47Z | |
| dc.date.issued | 2026-08-07 | |
| dc.description.abstract | Human Resource Information System (HRIS) APIs process highly sensitive financial data, making them prime targets for Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) attacks. Relying solely on perimeter defenses is insufficient to protect data at the object level. This study proposes and evaluates a Defense in Depth (DiD) architecture on a Golang-based REST API, specifically targeting the financial endpoint /payroll/{id}. The implemented security layers encompass JSON Web Token (JWT) signature validation and Role-Based Access Control (RBAC) as the first layer, Logic-Based Row-Level Security (RLS) integrated with GORM for object-level access isolation as the second layer, and AES-256-GCM encryption for Data at Rest protection as the final layer. To eliminate developer bias, the system evaluation adopted a GrayBox Testing approach utilizing a documented blind testing protocol via automated Burp Suite Intruder. The blind testing results demonstrated that without RLS, a lowprivileged employee successfully extracted unauthorized payroll records (HTTP 200 OK). Following the RLS implementation, the system strictly denied unauthorized access attempts (HTTP 403 Forbidden). The system also detected and rejected direct manipulation of the encrypted ciphertext (HTTP 500), confirming the integrity of the AES-256-GCM authentication tag. The integration of these layers effectively mitigated the targeted vulnerabilities, reducing the Common Vulnerability Scoring System (CVSS) v4.0 base scores from a maximum of 9.3 (Critical) and 7.1 (High) down to 0.0 (None) across all tested scenarios. This research provides a resilient, measurable security framework for modern HRIS architectures. | |
| dc.identifier.citation | IEEE | |
| dc.identifier.kodeprodi | KODEPRODI57302#Rekayasa Keamanan Siber | |
| dc.identifier.nidn | NIDN0013078703 | |
| dc.identifier.nim | NIM4332201042 | |
| dc.identifier.uri | https://repository.polibatam.ac.id//handle/PL29/5150 | |
| dc.language.iso | other | |
| dc.publisher | Politeknik Negeri Batam | |
| dc.subject | BOLA | |
| dc.subject | IDOR | |
| dc.subject | CVSS v4.0 | |
| dc.subject | Defense in Depth | |
| dc.subject | Row-Level Security | |
| dc.title | IMPLEMENTASI LOGIC-BASED ROW-LEVEL SECURITY DAN ROLE-BASED ACCESS CONTROL PADA REST API MENGGUNAKAN GOLANG DENGAN PENDEKATAN GRAY-BOX TESTING | |
| dc.title.alternative | IMPLEMENTATION OF LOGIC-BASED ROW-LEVEL SECURITY AND ROLE-BASED ACCESS CONTROL IN REST APIs USING GO WITH A GRAY-BOX TESTING APPROACH | |
| dc.type | Article |
Files
Original bundle
1 - 3 of 3
Loading...
- Name:
- Lembar_Pengesahan.pdf
- Size:
- 135.39 KB
- Format:
- Adobe Portable Document Format
- Description:
- Lembar_Pengesahan
Loading...
- Name:
- 4332201042_Article.pdf
- Size:
- 1.04 MB
- Format:
- Adobe Portable Document Format
- Description:
- Full Page Article
Loading...
- Name:
- Borang_Publikasi.pdf
- Size:
- 501.28 KB
- Format:
- Adobe Portable Document Format
- Description:
- Borang_Publikasi
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
