Analisis Komparatif Penggunaan IDS dan WAF Terhadap Serangan SQL Injection dan Brute Force: Tinjauan Literatur Sistematis

Authors

  • Hermawan Setiawan
  • Ahmad Muflih Izfatara Politeknik Siber dan Sandi Negara
  • Rahadian Ronggo Kusumo
  • Zamir Achmad Sachio
  • Moch Radhit Julian Randito

DOI:

https://doi.org/10.56706/ik.v20i2.159

Keywords:

Firewall Aplikasi Web, Injeksi SQL, Serangan Brute Force, Sistem Deteksi Intrusi, Tinjauan Literatur Sistematis

Abstract

Aplikasi web merupakan sasaran utama serangan SQL Injection (SQLi) dan Brute Force, sementara Intrusion Detection System (IDS) dan Web Application Firewall (WAF) berbasis tanda tangan terbatas dalam menghadapi serangan tersamar maupun serangan zero-day. Tinjauan Literatur Sistematis ini disusun mengikuti protokol PRISMA 2020 dan kerangka PICOC untuk memetakan tantangan penerapan, metode deteksi yang dominan, serta membandingkan metrik performa IDS dan WAF terhadap SQLi dan Brute Force. Pencarian pada tujuh basis data untuk publikasi 2021–2025, dengan penyaringan oleh dua penelaah independen dan penilaian kualitas lima butir, menghasilkan 14 studi primer yang dianalisis melalui sintesis tematik. Hasil tinjauan mengindikasikan bahwa perbandingan performa kedua sistem secara langsung rentan terhadap bias karena perbedaan lapisan operasional, unit analisis, dan dataset evaluasi. IDS berbasis Deep Learning hibrida melaporkan akurasi biner 99,84%–99,98% pada dataset arus jaringan yang hampir tidak memuat muatan SQLi, sedangkan WAF berbasis Machine Learning melaporkan akurasi 89,34%–97,57% pada muatan HTTP, dan pendekatan AI generatif memblokir 99% serangan SQLi yang sebelumnya lolos dengan 23 aturan tambahan. Penelitian ini mengusulkan kerangka normalisasi perbandingan berbasis strata, analisis base rate, dan daftar periksa pelaporan minimum delapan butir, serta menyimpulkan bahwa IDS dan WAF bersifat komplementer, bukan substitutif.

References

[1] B. R. Dawadi, B. Adhikari, and D. K. Srivastava, "Deep learning technique-enabled web application firewall for the detection of web attacks," Sensors, vol. 23, no. 4, art. 2073, 2023, doi: 10.3390/s23042073.

[2] A. Aldhaheri, F. Alwahedi, M. A. Ferrag, and A. Battah, "Deep learning for cyber threat detection in IoT networks: A review," Internet of Things and Cyber-Physical Systems, vol. 4, pp. 110–128, 2024, doi: 10.1016/j.iotcps.2023.09.003.

[3] M. Alghawazi, D. Alghazzawi, and S. Alarifi, "Detection of SQL injection attack using machine learning techniques: A systematic literature review," Journal of Cybersecurity and Privacy, vol. 2, no. 4, pp. 764–777, 2022, doi: 10.3390/jcp2040039.

[4] H. Kamal and M. Mashaly, "Enhanced hybrid deep learning models-based anomaly detection method for two-stage binary and multi-class classification of attacks in intrusion detection systems," Algorithms, vol. 18, no. 2, art. 69, 2025, doi: 10.3390/a18020069.

[5] R. Bace and P. Mell, "Intrusion detection systems," National Institute of Standards and Technology, NIST Special Publication 800-31, 2001, doi: 10.6028/NIST.SP.800-31.

[6] A. Coscia, V. Dentamaro, S. Galantucci, A. Maci, and G. Pirlo, "PROGESI: A PROxy grammar to enhance web application firewall for SQL injection prevention," IEEE Access, vol. 12, pp. 107689–107703, 2024, doi: 10.1109/ACCESS.2024.3438092.

[7] A. Shaheed and M. H. D. B. Kurdy, "Web application firewall using machine learning and features engineering," Security and Communication Networks, vol. 2022, art. 5280158, 2022, doi: 10.1155/2022/5280158.

[8] V. Babaey and A. Ravindran, "GenSQLi: A generative artificial intelligence framework for automatically securing web application firewalls against structured query language injection attacks," Future Internet, vol. 17, no. 1, art. 8, 2025, doi: 10.3390/fi17010008.

[9] K. Shang, W. He, and S. Zhang, "Review on security defense technology research in edge computing environment," Chinese Journal of Electronics, vol. 33, no. 1, pp. 1–18, 2024, doi: 10.23919/cje.2022.00.170.

[10] M. J. Page et al., "The PRISMA 2020 statement: An updated guideline for reporting systematic reviews," BMJ, vol. 372, art. n71, 2021, doi: 10.1136/bmj.n71.

[11] B. Kitchenham and S. Charters, "Guidelines for performing systematic literature reviews in software engineering," EBSE Technical Report EBSE-2007-01, Keele University and University of Durham, 2007.

[12] K. Scarfone and P. Mell, "Guide to intrusion detection and prevention systems (IDPS)," National Institute of Standards and Technology, NIST Special Publication 800-94, 2007, doi: 10.6028/NIST.SP.800-94.

[13] N. Gupta and A. Saikia, "Web application firewall," B.Tech Project Final Report, Dept. Comput. Sci. Eng., Indian Institute of Technology Kanpur, 2007.

[14] OWASP Foundation, "OWASP Top 10:2021 — The ten most critical web application security risks," 2021. [Daring]. Tersedia: https://owasp.org/Top10/

[15] M. A. Talukder et al., "Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction," Journal of Big Data, vol. 11, art. 33, 2024, doi: 10.1186/s40537-024-00886-w.

[16] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward generating a new intrusion detection dataset and intrusion traffic characterization," in Proc. 4th Int. Conf. Information Systems Security and Privacy (ICISSP), Funchal, Portugal, 2018, pp. 108–116, doi: 10.5220/0006639801080116.

[17] N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems," in Proc. Military Communications and Information Systems Conference (MilCIS), Canberra, Australia, 2015, pp. 1–6, doi: 10.1109/MilCIS.2015.7348942.

[18] M. Sarhan, S. Layeghy, and M. Portmann, "Towards a standard feature set for network intrusion detection system datasets," Mobile Networks and Applications, vol. 27, pp. 357–370, 2022, doi: 10.1007/s11036-021-01843-0.

[19] H. C. Altunay and Z. Albayrak, "A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks," Engineering Science and Technology, an International Journal, vol. 38, art. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.

[20] S. Axelsson, "The base-rate fallacy and the difficulty of intrusion detection," ACM Transactions on Information and System Security, vol. 3, no. 3, pp. 186–205, 2000, doi: 10.1145/357830.357849.

[21] R. Sommer and V. Paxson, "Outside the closed world: On using machine learning for network intrusion detection," in Proc. IEEE Symposium on Security and Privacy (S&P), Oakland, CA, USA, 2010, pp. 305–316, doi: 10.1109/SP.2010.25.

[22] T. Saito and M. Rehmsmeier, "The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets," PLOS ONE, vol. 10, no. 3, art. e0118432, 2015, doi: 10.1371/journal.pone.0118432.

[23] D. Arp, E. Quiring, F. Pendlebury, A. Warnecke, F. Pierazzi, C. Wressnegger, L. Cavallaro, and K. Rieck, "Dos and don'ts of machine learning in computer security," in Proc. 31st USENIX Security Symposium, Boston, MA, USA, 2022, pp. 3971–3988.

[24] G. Engelen, V. Rimmer, and W. Joosen, "Troubleshooting an intrusion detection dataset: The CICIDS2017 case study," in Proc. IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 2021, pp. 7–12, doi: 10.1109/SPW53761.2021.00009.

[25] M. Lanvin, P.-F. Gimenez, Y. Han, F. Majorczyk, L. Mé, and É. Totel, "Errors in the CICIDS2017 dataset and the significant differences in detection performances it makes," in Risks and Security of Internet and Systems (CRiSIS 2022), LNCS vol. 13857, Cham, Switzerland: Springer, 2023, pp. 18–33, doi: 10.1007/978-3-031-31108-6_2.

[26] C. Wohlin, "Guidelines for snowballing in systematic literature studies and a replication in software engineering," in Proc. 18th Int. Conf. Evaluation and Assessment in Software Engineering (EASE), London, UK, 2014, art. 38, doi: 10.1145/2601248.2601268.

[27] J. Cohen, "A coefficient of agreement for nominal scales," Educational and Psychological Measurement, vol. 20, no. 1, pp. 37–46, 1960, doi: 10.1177/001316446002000104.

[28] S. A. Wahab, S. Sultana, N. Tariq, M. Mujahid, J. A. Khan, and A. Mylonas, "A multi-class intrusion detection system for DDoS attacks in IoT networks using deep learning and transformers," Sensors, vol. 25, no. 15, art. 4845, 2025, doi: 10.3390/s25154845.

[29] N. Yoshimura, H. Kuzuno, Y. Shiraishi, and M. Morii, "DOC-IDS: A deep learning-based method for feature extraction and anomaly detection in network traffic," Sensors, vol. 22, no. 12, art. 4405, 2022, doi: 10.3390/s22124405.

[30] M. Aslam et al., "Adaptive machine learning based distributed denial-of-services attacks detection and mitigation system for SDN-enabled IoT," Sensors, vol. 22, no. 7, art. 2697, 2022, doi: 10.3390/s22072697.

[31] B. Alotaibi, "A survey on industrial Internet of Things security: Requirements, attacks, AI-based solutions, and edge computing opportunities," Sensors, vol. 23, no. 17, art. 7470, 2023, doi: 10.3390/s23177470.

[32] N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, "SMOTE: Synthetic minority over-sampling technique," Journal of Artificial Intelligence Research, vol. 16, pp. 321–357, 2002, doi: 10.1613/jair.953.

[33] H. He, Y. Bai, E. A. Garcia, and S. Li, "ADASYN: Adaptive synthetic sampling approach for imbalanced learning," in Proc. IEEE Int. Joint Conf. Neural Networks (IJCNN), Hong Kong, 2008, pp. 1322–1328, doi: 10.1109/IJCNN.2008.4633969.

Downloads

Submitted

26-02-2026

Accepted

27-08-2026

Published

25-09-2026

Issue

Section

Articles