Investigation framework of web applications vulnerabilities, attacks and protection techniques in structured query language injection attacks

被引:0
|
作者
Ali N.S. [1 ]
机构
[1] Information Technology Research and Development Centre, University of Kufa, AL-Najaf, Al-Kufa St
关键词
Defensive approaches; Detection; Investigation framework; Protection; Protection techniques; Security attacks; SQL injection; SQLI prevention; SQLIA; Techniques; Web applications; Web attacks; Web security; Web vulnerabilities; XSS;
D O I
10.1504/IJWMC.2018.091137
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web security has become a great challenge in recent years. Structured Query Language Injection Attack (SQLIA) is a prevalent and dominant class of the serious web application attacks. A crafter can easily get illegal access to the underlying database in the web application thereby gaining full control of the system and causing millions of dollars loss for corporations. In this paper, we provide a comprehensive study of web applications and investigate their vulnerabilities, attacks, and protection techniques against SQLIA Attacks. The study includes presenting a taxonomy of the SQLIAs investigation framework, conducts a detailed review of the various previous SQLI attacks protection techniques, as well as a summary and analysis of a critical review (strengths and weaknesses) of the detection and prevention techniques that have been done to address such attacks. Finally, it highlights and focuses on the critical and important directions or protection approaches that require more studies by future researchers. © 2018 Inderscience Enterprises Ltd.
引用
收藏
页码:103 / 122
页数:19
相关论文
共 39 条
  • [1] Analysis and Classification of SQL Injection Vulnerabilities and Attacks on Web Applications
    Sharma, Chandershekhar
    Jain, S. C.
    2014 INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING AND TECHNOLOGY RESEARCH (ICAETR), 2014,
  • [2] GenSQLi: A Generative Artificial Intelligence Framework for Automatically Securing Web Application Firewalls Against Structured Query Language Injection Attacks
    Babaey, Vahid
    Ravindran, Arun
    FUTURE INTERNET, 2025, 17 (01)
  • [3] Prediction of SQL Injection Attacks in Web Applications
    Arumugam, Chamundeswari
    Dwarakanathan, Varsha Bhargavi
    Gnanamary, S.
    Neyveli, Vishalraj Natarajan
    Ramesh, Rohit Kanakuppaliyalil
    Kandhavel, Yeshwanthraa
    Balakrishnan, Sadhanandhan
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2019, PT IV, 2019, 11622 : 496 - 505
  • [4] The essence of command injection attacks in web applications
    Su, ZD
    Wassermann, G
    ACM SIGPLAN NOTICES, 2006, 41 (01) : 372 - 382
  • [5] A comparative analysis and performance evaluation of web application protection techniques against injection attacks
    Ali, Nabeel Salih
    Bin Shibghatullah, Abdul Samad
    Alhilali, Ahmed Hazim
    Al-Khammasi, Salam
    Kadhim, Mohammed Falih
    Fatlawi, Hayder K.
    INTERNATIONAL JOURNAL OF MOBILE COMMUNICATIONS, 2020, 18 (02) : 196 - 228
  • [6] Detection and Prevention of SQL Injection Attacks on Web Applications
    Fouad, Yasser
    Elshazly, Khaled
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (08): : 1 - 7
  • [7] Analysis of SQL injection attacks in the cloud and in WEB applications
    Kumar, Animesh
    Dutta, Sandip
    Pranav, Prashant
    SECURITY AND PRIVACY, 2024, 7 (03)
  • [8] Protecting Web Applications from SQL Injection Attacks by using Framework and Database Firewall
    Manikanta, Yakkala V. Naga
    Sardana, Anjali
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 609 - 613
  • [9] Reducing Structured Query Language Injection Vulnerabilities Through Functional Programming Principles
    Piscatello, Michael
    SOUTHEASTCON 2023, 2023, : 425 - 432
  • [10] HMM-Web: a framework for the detection of attacks against Web applications
    Corona, Igino
    Ariu, Davide
    Giacinto, Giorgio
    2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 747 - 752