Ruri Ashari Dalimunthe, Sahren Sahren


SQL Injection (SQLI) is the main type of attack that will threaten the integrity, confidentiality, and authenticity or functionality of database-based web applications. This allows an attacker to gain unauthorized access to a back-end database by exploiting vulnerabilities in the system to carry out attacks and access existing resources. Therefore, the best prevention techniques against SQL Injection attacks are needed to protect an individual or organizational data from hacking. In this study, using two security techniques, namely using the Intrusion Detection System as a sensor that will detect if an SQL Injection attack occurs, and using a web-based firewall (ModSecurity) as a security system that will block attacks. The purpose of this research is to build a capable security system that will detect and block any SQL Injection attacks against the database. the proposed system was tested using the Sqlmapproject attack tool. Sqlmapproject is used to attack web applications before and after protection. The results show that the proposed security system is functioning properly and can protect the database system on the web well, high performance, and efficiency.

Full Text:



