Investigation framework of web applications vulnerabilities, attacks and protection techniques in structured query language injection attacks

被引:0
|
作者
Ali N.S. [1 ]
机构
[1] Information Technology Research and Development Centre, University of Kufa, AL-Najaf, Al-Kufa St
来源
International Journal of Wireless and Mobile Computing | 2018年 / 14卷 / 02期
关键词
Defensive approaches; Detection; Investigation framework; Protection; Protection techniques; Security attacks; SQL injection; SQLI prevention; SQLIA; Techniques; Web applications; Web attacks; Web security; Web vulnerabilities; XSS;
D O I
10.1504/IJWMC.2018.091137
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web security has become a great challenge in recent years. Structured Query Language Injection Attack (SQLIA) is a prevalent and dominant class of the serious web application attacks. A crafter can easily get illegal access to the underlying database in the web application thereby gaining full control of the system and causing millions of dollars loss for corporations. In this paper, we provide a comprehensive study of web applications and investigate their vulnerabilities, attacks, and protection techniques against SQLIA Attacks. The study includes presenting a taxonomy of the SQLIAs investigation framework, conducts a detailed review of the various previous SQLI attacks protection techniques, as well as a summary and analysis of a critical review (strengths and weaknesses) of the detection and prevention techniques that have been done to address such attacks. Finally, it highlights and focuses on the critical and important directions or protection approaches that require more studies by future researchers. © 2018 Inderscience Enterprises Ltd.
引用
收藏
页码:103 / 122
页数:19
相关论文
共 39 条
  • [31] Cross Channel Scripting and Code Injection Attacks on Web and Cloud-Based Applications: A Comprehensive Review
    Indushree, M.
    Kaur, Manjit
    Raj, Manish
    Shashidhara, R.
    Lee, Heung-No
    SENSORS, 2022, 22 (05)
  • [32] Securing transportation web applications: An AI-driven approach to detect and mitigate SQL injection attacks
    Mohamed, Nachaat
    JOURNAL OF TRANSPORTATION SECURITY, 2024, 17 (01)
  • [33] A Hybrid Approach to Detect Injection Attacks on Server-side Applications using Data Mining Techniques
    Ahmed, Abu Syeed Sajid
    Shachi, Mehjabeen
    Brishty, Afsana Afrin
    Siddiqui, Nurnaby
    Sakib, Nazmus
    2021 3RD INTERNATIONAL CONFERENCE ON SUSTAINABLE TECHNOLOGIES FOR INDUSTRY 4.0 (STI), 2021,
  • [34] The quality improvement method for detecting attacks on web applications using pre-trained natural language models
    Kovaleva, O. A.
    Samokhvalov, A., V
    Liashkov, M. A.
    Pchelintsev, S. Yu.
    IZVESTIYA OF SARATOV UNIVERSITY MATHEMATICS MECHANICS INFORMATICS, 2024, 24 (03): : 442 - 451
  • [35] Enhancing Structured Query Language Injection Detection with Trustworthy Ensemble Learning and Boosting Models Using Local Explanation Techniques
    Le, Thi-Thu-Huong
    Hwang, Yeonjeong
    Choi, Changwoo
    Wardhani, Rini Wisnu
    Putranto, Dedy Septono Catur
    Kim, Howon
    ELECTRONICS, 2024, 13 (22)
  • [36] A deliberately insecure RDF-based Semantic Web application framework for teaching SPARQL/SPARUL injection attacks and defense mechanisms
    Asghar, Hira
    Anwar, Zahid
    Latif, Khalid
    COMPUTERS & SECURITY, 2016, 58 : 63 - 82
  • [37] Implementation of techniques, standards and safety recommendations to prevent XSS and SQL injection attacks in Java']Java EE RESTful applications
    Guaman, Daniel
    Guaman, Franco
    Jaramillo, Danilo
    Correa, Roddy
    NEW ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2016, 444 : 691 - 706
  • [38] Denial-of-Service Attacks Pre-Emptive and Detection Framework for Synchrophasor Based Wide Area Protection Applications
    Chawla, Astha
    Singh, Animesh
    Agrawal, Prakhar
    Panigrahi, Bijaya Ketan
    Bhalja, Bhavesh R.
    Paul, Kolin
    IEEE SYSTEMS JOURNAL, 2022, 16 (01): : 1570 - 1581
  • [39] ConvXSS: A deep learning-based smart ICT framework against code injection attacks for HTML']HTML5 web applications in sustainable smart city infrastructure
    Kuppa, Koundinya
    Dayal, Anushka
    Gupta, Shashank
    Dua, Amit
    Chaudhary, Pooja
    Rathore, Shailendra
    SUSTAINABLE CITIES AND SOCIETY, 2022, 80