A Mapping-based Podel for Preventing Cross Site Scripting and SQL Injection Attacks on Web Application and its Impact Analysis

被引:0
|
作者
Pandurang, Rathod Mahesh [1 ]
Karia, Deepak C. [2 ]
机构
[1] SPIT, Dept Comp Engn, Bombay 400058, Maharashtra, India
[2] SPIT, Dept Elect Engn, Bombay 400058, Maharashtra, India
关键词
Intrusion Detection System (IDS); SQL Injection Attack; Cross Site Scripting (XSS) Attack; Mapping model;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Web applications provide vast category of functionalities and usefulness. As more and more sensitive data is available over the web, crackers are getting attracted in such data revealing which can root immense harm. SQL injection is one of such type of attack. This attack can be used to infiltrate the back-end of any web application that may lead to modification of database or disclosing significant information. Attacker can obfuscate the input given to the web application using Cross site scripting attack that may direct to distortion in the web page view. Three tier web applications can be categorized into static and dynamic web application for detecting and preventing these types of attacks. Mapping model in which requests are mapped on generated queries can be used productively to detect such kind of attacks and prevention logic can be applied for attack removal. The impact measurement of container based approach on the web server is measured using autobench tool, the parameters used are network throughput and response time.
引用
收藏
页码:414 / 418
页数:5
相关论文
共 20 条
  • [1] Impact Analysis of Preventing Cross Site Scripting and SQL Injection Attacks on Web Application
    Pandurang, Rathod Mahesh
    Karia, Deepak C.
    2015 IEEE BOMBAY SECTION SYMPOSIUM (IBSS), 2015,
  • [2] Automatic Creation of SQL Injection and Cross-Site Scripting Attacks
    Kiezun, Adam
    Guo, Philip J.
    Jayaraman, Karthick
    Ernst, Michael D.
    2009 31ST INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, PROCEEDINGS, 2009, : 199 - +
  • [3] A Novel Approach for Detection of SQL Injection and Cross Site Scripting Attacks
    Sonewar, Piyush A.
    Mhetre, Nalini A.
    2015 INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING (ICPC), 2015,
  • [4] An Automaton based Approach for forestalling Cross Site Scripting attacks in web application
    Suju, D. Arul
    Gandhi, G. Meera
    2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2015,
  • [5] Static Analysis Approaches to Detect SQL Injection and Cross Site Scripting Vulnerabilities in Web Applications: A Survey
    Gupta, Mukesh Kumar
    Govil, M. C.
    Singh, Girdhari
    2014 RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2014,
  • [6] Finding SQL Injection and Cross Site Scripting Vulnerabilities with Diverse Static Analysis Tools
    Algaith, Areej
    Nunes, Paulo
    Fonseca, Jose
    Gashi, Ilir
    Vieira, Marco
    2018 14TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2018), 2018, : 57 - 64
  • [7] Mining SQL Injection and Cross Site Scripting Vulnerabilities using Hybrid Program Analysis
    Shar, Lwin Khin
    Tan, Hee Beng Kuan
    Briand, Lionel C.
    PROCEEDINGS OF THE 35TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2013), 2013, : 642 - 651
  • [8] Automatically Repairing Web Application Firewalls Based on Successful SQL Injection Attacks
    Appelt, Dennis
    Panichella, Annibale
    Briand, Lionel
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2017, : 339 - 350
  • [9] Secured Web Application Using Combination of Query Tokenization and Adaptive Method in Preventing SQL Injection Attacks
    Abu Othman, Noor Ashitah
    Ali, Fakariah Hani Mohd
    Noh, Mashyum Binti Mohd
    2014 INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATIONS, AND CONTROL TECHNOLOGY (I4CT), 2014, : 472 - 476
  • [10] A Security Analysis Tool For Web Application Reinforcement Against SQL Injection Attacks (SQLIAs)
    Lashkaripour, Z.
    Bafghi, A. Ghaemi
    2013 10TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2013,