Analysis on Injection Vulnerabilities of Web Application

被引:1
|
作者
Yadav, Nilesh [1 ]
Shekokar, Narendra [1 ]
机构
[1] DJ Sanghvi Coll Engn, Dept Comp Engn, Mumbai, Maharashtra, India
关键词
Web application; Injection vulnerability; Attack; Security; OWASP;
D O I
10.1007/978-981-10-8339-6_2
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The number of Internet users has incredible grown. Web applications are normally utilized in various sectors like Ecommerce, Banking, and Military. It is collection of thousands of lines of program, which habitually contain some bugs. Part of them have impact on security and can lead to complete control of the application by an attacker. While in client-server communication, the attacker inputs the vulnerable content into the application, these unnoticed vulnerabilities cause financial losses to organizations. Thus, mitigating such an attack is vital to evade mischievous penalties. An enormous research work on application security has been continuously going on but every defense has its own advantages and disadvantages. The aim of this paper is to study and consolidate the understanding of injection vulnerabilities and its mitigation technique. Different approaches proposed by researchers are analyzed here and discussed about the observed pitfalls present in the existing solutions.
引用
收藏
页码:13 / 22
页数:10
相关论文
共 50 条
  • [41] A New Framework of Security Vulnerabilities Detection in PHP Web Application
    Zhao, Jingling
    Gong, Rulin
    2015 9TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING IMIS 2015, 2015, : 271 - 276
  • [42] Fault-based testing for discovering SQL injection vulnerabilities in web applications
    Alsmadi I.
    AlEroud A.
    Saifan A.A.
    International Journal of Information and Computer Security, 2021, 16 (1-2): : 51 - 62
  • [43] A Rejection-Based Approach for Detecting SQL Injection Vulnerabilities in Web Applications
    Saoudi, Lalia
    Adi, Kamel
    Boudraa, Younes
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2019, 2020, 12056 : 379 - 386
  • [44] A Search-based Testing Approach for XML Injection Vulnerabilities in Web Applications
    Jan, Sadeeq
    Nguyen, Cu D.
    Arcuri, Andrea
    Briand, Lionel
    2017 10TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2017, : 356 - 366
  • [45] Confeagle: Automated Analysis of Configuration Vulnerabilities in Web Applications
    Eshete, Birhanu
    Villafiorita, Adolfo
    Weldemariam, Komminist
    Zulkernine, Mohammad
    2013 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (SERE), 2013, : 188 - 197
  • [46] Mapping and Analysis of Common Vulnerabilities in Popular Web Servers
    Barocsai, Matyas
    Can, Johan
    Karresand, Martin
    Nadjm-Tehrani, Simin
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, CRITIS 2023, 2024, 14599 : 3 - 22
  • [47] A Practical Analysis of TLS Vulnerabilities in Korea Web Environment
    Jeong, Jongmin
    Kwon, Hyunsoo
    Shin, Hyungjune
    Hur, Junbeom
    INFORMATION SECURITY APPLICATIONS, WISA 2016, 2017, 10144 : 112 - 123
  • [48] Analysis of Vulnerabilities in College Web-Based System
    Nam, Younsu
    Choi, Sunoh
    ELECTRONICS, 2024, 13 (12)
  • [49] A static analysis framework for detecting SQL injection vulnerabilities
    Fu, Xiang
    Lu, Xin
    Peltsverger, Boris
    Chen, Shijun
    Qian, Kai
    Tao, Lixin
    COMPSAC 2007: THE THIRTY-FIRST ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOL I, PROCEEDINGS, 2007, : 87 - +
  • [50] Web Application Security Vulnerabilities Detection Approaches: a Systematic Mapping Study
    Rafique, Sajjad
    Humayun, Mamoona
    Hamid, Bushra
    Abbas, Ansar
    Akhtar, Muhammad
    Iqbal, Kamil
    2015 16TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD), 2015, : 469 - 474