Analysis on Injection Vulnerabilities of Web Application

被引:1
|
作者
Yadav, Nilesh [1 ]
Shekokar, Narendra [1 ]
机构
[1] DJ Sanghvi Coll Engn, Dept Comp Engn, Mumbai, Maharashtra, India
关键词
Web application; Injection vulnerability; Attack; Security; OWASP;
D O I
10.1007/978-981-10-8339-6_2
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The number of Internet users has incredible grown. Web applications are normally utilized in various sectors like Ecommerce, Banking, and Military. It is collection of thousands of lines of program, which habitually contain some bugs. Part of them have impact on security and can lead to complete control of the application by an attacker. While in client-server communication, the attacker inputs the vulnerable content into the application, these unnoticed vulnerabilities cause financial losses to organizations. Thus, mitigating such an attack is vital to evade mischievous penalties. An enormous research work on application security has been continuously going on but every defense has its own advantages and disadvantages. The aim of this paper is to study and consolidate the understanding of injection vulnerabilities and its mitigation technique. Different approaches proposed by researchers are analyzed here and discussed about the observed pitfalls present in the existing solutions.
引用
收藏
页码:13 / 22
页数:10
相关论文
共 50 条
  • [21] Impact of secure programming on web application vulnerabilities
    Rexha, Blerim
    Halili, Arbnor
    Rrmoku, Korab
    Imeraj, Dren
    2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER GRAPHICS, VISION AND INFORMATION SECURITY (CGVIS), 2015, : 61 - 66
  • [22] Web Application Vulnerabilities Detection Techniques Survey
    Khochare, Nilesh
    Chalurkar, Satish
    Meshram, B. B.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (06): : 71 - 75
  • [23] Finding Web Application Vulnerabilities with an Ensemble Fuzzing
    Caseirito, Joao
    Medeiros, Iberia
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS - SUPPLEMENTAL VOL (DSN 2021), 2021, : 19 - 20
  • [24] Detection of Web Application Vulnerabilities Accelerated by GPU
    Li, Shaotao
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MECHANICAL MATERIALS AND MANUFACTURING ENGINEERING (MMME 2016), 2016, 79 : 329 - 331
  • [25] Pixy: A static analysis tool for detecting Web application vulnerabilities - (Short paper)
    Jovanovic, Nenad
    Kruegel, Christopher
    Kirda, Engin
    2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2006, : 258 - +
  • [26] A Static Backward Taint Data Analysis Method for Detecting Web Application Vulnerabilities
    Yan, Xuexiong
    Ma, Hengtai
    Wang, Qingxian
    2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2017, : 1138 - 1141
  • [27] Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    Antunes, Nuno
    Laranjeiro, Nuno
    Vieira, Marco
    Madeira, Henrique
    2009 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, 2009, : 260 - 267
  • [28] SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the Web
    Shcherbakov, Mikhail
    Balliu, Musard
    28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [29] A Study on Web Application Security and Detecting Security Vulnerabilities
    Kumar, Sandeep
    Mahajan, Renuka
    Kumar, Naresh
    Khatri, Sunil Kumar
    2017 6TH INTERNATIONAL CONFERENCE ON RELIABILITY, INFOCOM TECHNOLOGIES AND OPTIMIZATION (TRENDS AND FUTURE DIRECTIONS) (ICRITO), 2017, : 451 - 455
  • [30] Access Control Vulnerabilities Detection for Web Application Components
    Wang, Qian
    Sun, Jinan
    Wang, Chen
    Zhang, Shikun
    Xuanyuan, Sisi
    Zheng, Bin
    2020 IEEE 6TH INT CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / 6TH IEEE INT CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) / 5TH IEEE INT CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2020, : 24 - 28