Abstract
This research aims to identify and mitigate security vulnerabilities in the Hospital Information System (SIMRS) using the OWASP Web Security Testing Guide (WSTG) v4.2 based testing method. With the help of the OWASP ZAP tool, various vulnerabilities were identified, such as SQL Injection, weaknesses in session management, lack of security attributes in cookies, and disclosure of sensitive information through URLs or code comments. SQL Injection was identified as the highest risk vulnerability, as it potentially allows attackers to access, manipulate, or delete sensitive data in the database. In addition, weaknesses in cookie attributes, such as HttpOnly and SameSite, and the absence of an anti-CSRF mechanism, indicate potential threats in the form of Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). The implementation of a solution based on WSTG v4.2 involves steps such as the implementation of HTTPS encryption, the use of prepared statements for database interaction, the application of security headers such as Content-Security-Policy (CSP), and input validation to reduce the risk of XSS. In addition, code audits were conducted to remove sensitive comments, while hidden files or unnecessary backups were removed to minimize the potential for information leakage. Test results after the implementation of the solution showed a significant improvement in the security level of the application. This research proves that the WSTG v4.2-based approach can provide comprehensive and systematic guidance in web application security testing. With these results, organizations, particularly in the healthcare sector, can ensure better protection of patient data and comply with applicable information security standards.Penelitian ini bertujuan untuk mengidentifikasi dan memitigasi kerentanan keamanan pada Sistem Informasi Rumah Sakit (SIMRS) menggunakan metode pengujian berbasis OWASP Web Security Testing Guide (WSTG) v4.2. Dengan bantuan alat OWASP ZAP, berbagai kerentanan berhasil diidentifikasi, seperti SQL Injection, kelemahan dalam manajemen sesi, ketiadaan atribut keamanan pada cookie, dan pengungkapan informasi sensitif melalui URL atau komentar kode. SQL Injection teridentifikasi sebagai kerentanan dengan risiko tertinggi, karena berpotensi memungkinkan pelaku serangan untuk mengakses, memanipulasi, atau menghapus data sensitif dalam basis data. Selain itu, kelemahan pada atribut cookie, seperti HttpOnly dan SameSite, serta ketiadaan mekanisme anti-CSRF, mengindikasikan potensi ancaman berupa Cross-Site Scripting (XSS) dan Cross-Site Request Forgery (CSRF). Penerapan solusi berdasarkan WSTG v4.2 melibatkan langkah-langkah seperti implementasi enkripsi HTTPS, penggunaan prepared statements untuk interaksi basis data, penerapan header keamanan seperti Content-Security-Policy (CSP), dan validasi input untuk mengurangi risiko XSS. Selain itu, audit kode dilakukan untuk menghapus komentar sensitif, sementara file tersembunyi atau cadangan yang tidak diperlukan dihapus untuk meminimalkan potensi kebocoran informasi. Hasil pengujian setelah implementasi solusi menunjukkan peningkatan signifikan dalam tingkat keamanan aplikasi. Penelitian ini membuktikan bahwa pendekatan berbasis WSTG v4.2 dapat memberikan panduan yang komprehensif dan sistematis dalam pengujian keamanan aplikasi web. Dengan hasil ini, organisasi, khususnya di sektor kesehatan, dapat memastikan perlindungan data pasien yang lebih baik dan mematuhi standar keamanan informasi yang berlaku.
Cite
CITATION STYLE
Widyaningrum, B. N., Maya Rani, D., & Kurnia Ramadhani, L. (2024). Analysis of the OWASP V4.2 Method in Hospital Information System Security Testing. MEDIKA TRADA, 5(2), 87–97. https://doi.org/10.59485/jtemp.v5i2.99
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.