
IMPLEMENTATION OF A COMPUTER SECURITY INCIDENT RESPONSE TEAM (CSIRT) FOR SQL INJECTION ATTACK PROTECTION IN HIGHER EDUCATION ENVIRONMENTS
The poster presents a research project on the implementation of a Computer Security Incident Response Team (CSIRT) framework integrated with machine learning to detect and respond to SQL Injection (SQLi) attacks in higher education environments. The study addresses the increasing cybersecurity risks faced by web-based academic information systems by combining intelligent attack detection with a structured incident response process based on the NIST Incident Response Framework. The research methodology consists of dataset collection, data preprocessing using TF-IDF feature extraction, machine learning model development, performance evaluation, SQL Injection attack simulation using DVWA and XAMPP, and CSIRT implementation. Three classification algorithms—Decision Tree, Support Vector Machine (SVM), and Naive Bayes—were evaluated using Accuracy, Precision, Recall, F1-Score, and AUC metrics. The experimental results show that the Decision Tree model achieved the highest performance with 97% accuracy and an AUC of 0.9816. SQL Injection attack simulations successfully demonstrated the exploitation of vulnerable web applications, while the proposed CSIRT framework effectively supported the incident response lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and post-incident activities. Overall, the proposed approach enhances cybersecurity readiness by integrating machine learning-based threat detection with standardized incident response procedures, providing a comprehensive strategy for protecting web applications in higher education institutions against SQL Injection attacks.
Creators & Authors
Keysa Fikri Muharsa
09011282227043