Analysis on Injection Vulnerabilities of Web Application

被引:1
|
作者
Yadav, Nilesh [1 ]
Shekokar, Narendra [1 ]
机构
[1] DJ Sanghvi Coll Engn, Dept Comp Engn, Mumbai, Maharashtra, India
关键词
Web application; Injection vulnerability; Attack; Security; OWASP;
D O I
10.1007/978-981-10-8339-6_2
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The number of Internet users has incredible grown. Web applications are normally utilized in various sectors like Ecommerce, Banking, and Military. It is collection of thousands of lines of program, which habitually contain some bugs. Part of them have impact on security and can lead to complete control of the application by an attacker. While in client-server communication, the attacker inputs the vulnerable content into the application, these unnoticed vulnerabilities cause financial losses to organizations. Thus, mitigating such an attack is vital to evade mischievous penalties. An enormous research work on application security has been continuously going on but every defense has its own advantages and disadvantages. The aim of this paper is to study and consolidate the understanding of injection vulnerabilities and its mitigation technique. Different approaches proposed by researchers are analyzed here and discussed about the observed pitfalls present in the existing solutions.
引用
收藏
页码:13 / 22
页数:10
相关论文
共 50 条
  • [1] A Static Analysis Tool for Detecting Web Application Injection Vulnerabilities for ASP Program
    Zhang Xin-hua
    Wang Zhi-jian
    2010 2ND INTERNATIONAL CONFERENCE ON E-BUSINESS AND INFORMATION SYSTEM SECURITY (EBISS 2010), 2010, : 116 - 120
  • [2] LogInjector: Detecting Web Application Log Injection Vulnerabilities
    Pan, Zulie
    Chen, Yu
    Chen, Yuanchao
    Shen, Yi
    Li, Yang
    APPLIED SCIENCES-BASEL, 2022, 12 (15):
  • [3] Sound and precise analysis of web applications for injection vulnerabilities
    Wassermann, Gary
    Su, Zhendong
    ACM SIGPLAN NOTICES, 2007, 42 (06) : 32 - 41
  • [4] Sound and Precise Analysis of Web Applications for Injection Vulnerabilities
    Wassermann, Gary
    Su, Zhendong
    PLDI'07: PROCEEDINGS OF THE 2007 ACM SIGPLAN CONFERENCE ON PROGRAMMING LANGUAGE DESIGN AND IMPLEMENTATION, 2007, : 32 - 41
  • [5] Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection
    De Meo, Federico
    Rocchetto, Marco
    Vigano, Luca
    SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 179 - 195
  • [6] Analysis and Classification of SQL Injection Vulnerabilities and Attacks on Web Applications
    Sharma, Chandershekhar
    Jain, S. C.
    2014 INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING AND TECHNOLOGY RESEARCH (ICAETR), 2014,
  • [7] An extensible framework for web application vulnerabilities visualization and analysis
    Dang, Tran Tri
    Dang, Tran Khanh
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8860 : 86 - 96
  • [8] A hybrid analysis framework for detecting web application vulnerabilities
    Monga, Mattia
    Paleari, Roberto
    Passerini, Emanuele
    2009 ICSE WORKSHOP ON SOFTWARE ENGINEERING FOR SECURE SYSTEMS, 2009, : 25 - 32
  • [9] An Extensible Framework for Web Application Vulnerabilities Visualization and Analysis
    Tran Tri Dang
    Tran Khanh Dang
    FUTURE DATA AND SECURITY ENGINEERING, FDSE 2014, 2014, 8860 : 86 - 96
  • [10] Detecting SQL Injection Vulnerabilities in Web Services
    Antunes, Nuno
    Vieira, Marco
    LADC: 2009 4TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING, 2009, : 17 - 24