Journal Innovations Computer Science
Vol. 4 No. 2 (2025): November

Security Analysis of Midtrans Payment Gateway API against DDoS Attack and Rate Limiting Technique Using Node.js

Widianto Putro, Faris (Unknown)
Matheos Sarimole, Frencis (Unknown)



Article Info

Publish Date
30 Nov 2025

Abstract

The development of digital transaction services has led to the widespread use of APIs in payment systems, including payment gateway services such as Midtrans. However, the open access to APIs also increases the risk of cyber attacks, one of which is Distributed Denial of Service (DDoS) which can destabilize the system and reduce user confidence. This research aims to analyze the potential DDoS threats to the Midtrans API and explore the application of rate limiting techniques using Node.js as one of the mitigation measures. The methodology used is a waterfall approach, which includes requirements analysis, system design, implementation, testing, and evaluation. The test design is done through simulating DDoS attacks on API endpoints, both before and after the application of rate limiting, by measuring parameters such as the number of requests, response time, and request success rate. It is hoped that this research can provide a clear picture of the importance of API protection in digital payment systems, and produce a technical approach that can be used as a reference in developing a secure and reliable system. This research is also expected to make practical and theoretical contributions in the field of API security and digital service traffic management.

Copyrights © 2025






Journal Info

Abbrev

jics

Publisher

Subject

Computer Science & IT

Description

Journal Innovations Computer Science (JICS) is a peer-reviewed, twice-annually published international journal that focuses on innovative, original, previously unpublished, experimental or theoretical research concepts. Journal Innovations Computer Science (JICS) covers all areas of computer & ...