IMPLEMENTASI LOGIC-BASED ROW-LEVEL SECURITY DAN ROLE-BASED ACCESS CONTROL PADA REST API MENGGUNAKAN GOLANG DENGAN PENDEKATAN GRAY-BOX TESTING

dc.contributor.advisorKurniawan, Dwi Ely
dc.contributor.authorFudail, Zabran
dc.date.accessioned2026-08-14T07:51:47Z
dc.date.issued2026-08-07
dc.description.abstractHuman Resource Information System (HRIS) APIs process highly sensitive financial data, making them prime targets for Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) attacks. Relying solely on perimeter defenses is insufficient to protect data at the object level. This study proposes and evaluates a Defense in Depth (DiD) architecture on a Golang-based REST API, specifically targeting the financial endpoint /payroll/{id}. The implemented security layers encompass JSON Web Token (JWT) signature validation and Role-Based Access Control (RBAC) as the first layer, Logic-Based Row-Level Security (RLS) integrated with GORM for object-level access isolation as the second layer, and AES-256-GCM encryption for Data at Rest protection as the final layer. To eliminate developer bias, the system evaluation adopted a GrayBox Testing approach utilizing a documented blind testing protocol via automated Burp Suite Intruder. The blind testing results demonstrated that without RLS, a lowprivileged employee successfully extracted unauthorized payroll records (HTTP 200 OK). Following the RLS implementation, the system strictly denied unauthorized access attempts (HTTP 403 Forbidden). The system also detected and rejected direct manipulation of the encrypted ciphertext (HTTP 500), confirming the integrity of the AES-256-GCM authentication tag. The integration of these layers effectively mitigated the targeted vulnerabilities, reducing the Common Vulnerability Scoring System (CVSS) v4.0 base scores from a maximum of 9.3 (Critical) and 7.1 (High) down to 0.0 (None) across all tested scenarios. This research provides a resilient, measurable security framework for modern HRIS architectures.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN0013078703
dc.identifier.nimNIM4332201042
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5150
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectBOLA
dc.subjectIDOR
dc.subjectCVSS v4.0
dc.subjectDefense in Depth
dc.subjectRow-Level Security
dc.titleIMPLEMENTASI LOGIC-BASED ROW-LEVEL SECURITY DAN ROLE-BASED ACCESS CONTROL PADA REST API MENGGUNAKAN GOLANG DENGAN PENDEKATAN GRAY-BOX TESTING
dc.title.alternativeIMPLEMENTATION OF LOGIC-BASED ROW-LEVEL SECURITY AND ROLE-BASED ACCESS CONTROL IN REST APIs USING GO WITH A GRAY-BOX TESTING APPROACH
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan.pdf
Size:
135.39 KB
Format:
Adobe Portable Document Format
Description:
Lembar_Pengesahan
Loading...
Thumbnail Image
Name:
4332201042_Article.pdf
Size:
1.04 MB
Format:
Adobe Portable Document Format
Description:
Full Page Article
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
501.28 KB
Format:
Adobe Portable Document Format
Description:
Borang_Publikasi

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: