Implementation of Fault Injection Based Security Testing to Find Potential Security Vulnerabilities on XYZ Platform
andi purnomo, Faiz Hanafi
Abstract
Security Disclosure has become an important program in identifying and addressing vulnerabilities in software systems across various organizations and institutions by providing an opportunity for system testing through collaboration with external parties. This research aims to provide a deeper understanding of security disclosure through the Security Disclosure program on Platform XYZ, with a focus on Fault Injection techniques through parameter manipulation to discover IDOR (Insecure Direct Object Reference) vulnerabilities. The research begins by explaining the importance of the Security Disclosure program in the context of software security and system improvement. Furthermore, this study conducts testing on Fault Injection techniques through parameter manipulation, which is used to search for IDOR vulnerabilities on Platform XYZ. By manipulating input parameters, researchers can test the system by inducing unexpected behavior that can reveal sensitive information or grant unauthorized access to permissions. Case studies and real-world examples are used to demonstrate the effectiveness and impact of Fault Injection techniques in enhancing system security. The research findings have shown a high level of IDOR vulnerability with an impact on thousands of users. This research also highlights the importance of broader understanding of software security and security awareness for organizations and individual users. It is expected that this research will contribute to improving understanding of security disclosure and Fault Injection techniques through parameter manipulation, as well as promoting higher security awareness in protecting software systems from attacks and safeguarding sensitive user data on Platform XYZ.
Format : Jurnal Ilmiah Teknik Informatika Fakultas Ilmu Komputer Universitas Mercu Buana Jl. Raya Meruya Selatan, Kembangan, Jakarta 11650 Tlp./Fax: +62215840816 http://publikasi.mercubuana.ac.id/index.php/format