A Security Analysis Tool For Web Application Reinforcement Against SQL Injection Attacks (SQLIAs)

被引:0
|
作者
Lashkaripour, Z. [1 ]
Bafghi, A. Ghaemi [1 ]
机构
[1] Ferdowsi Univ Mashhad, Dept Comp, Data & Commun Secur Lab, Fac Engn, Mashhad, Iran
关键词
Web application; SQLIA; transformation; static analysis; detection;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In SQLIA, attacker injects an input in the query in order to change the structure of the query intended by the programmer and therefore, gain access to the data in the underlying database. Due to the significance of the stored data, web application's security against SQLIA is vital. In this paper we propose a tool that is capable of reporting the transformations needed to reinforce the security of a Java-based web application and its database against SQLIAs. This tool which is based on static analysis and runtime validation uses our new technique for detection and prevention of SQLIAs. In our technique user inputs in SQL queries are removed and some information is gathered in order to make the detection easier and faster at runtime. According to these information the tool reports the transformations needed and the location of the transformations in source code and therefore after applying the transformations the result would be a reinforced web application against SQLIAs.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] A Simple and Fast Technique for Detection and Prevention of SQL Injection Attacks (SQLIAs)
    Lashkaripour, Z.
    Bafghi, A. Ghaemi
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (05): : 53 - 66
  • [2] Research on SQL Injection Attacks and Defense in Web Application
    Dai, Hong
    Guo, Ying-Hui
    2015 International Conference on Software Engineering and Information System (SEIS 2015), 2015, : 420 - 426
  • [3] Mitigation from SQL Injection Attacks on Web Server using Open Web Application Security Project Framework
    Fadlil, A.
    Riadi, I.
    Mu'min, M. A.
    INTERNATIONAL JOURNAL OF ENGINEERING, 2024, 37 (04): : 635 - 645
  • [4] Web application security by SQL injection detection tools
    Tajpour, A., 2012, International Journal of Computer Science Issues (IJCSI) (09): : 2 - 3
  • [5] Analysis of SQL injection attacks in the cloud and in WEB applications
    Kumar, Animesh
    Dutta, Sandip
    Pranav, Prashant
    SECURITY AND PRIVACY, 2024, 7 (03)
  • [6] Toward an SDN-Based Web Application Firewall: Defending against SQL Injection Attacks
    Alotaibi, Fahad M.
    Vassilakis, Vassilios G.
    FUTURE INTERNET, 2023, 15 (05)
  • [7] A Detective Tool against SQL Injection Attacks Based on Static Analysis and Dynamic Monitor
    Liu, Zijian
    Xu, Lei
    2013 10TH WEB INFORMATION SYSTEM AND APPLICATION CONFERENCE (WISA 2013), 2013, : 195 - +
  • [8] Impact Analysis of Preventing Cross Site Scripting and SQL Injection Attacks on Web Application
    Pandurang, Rathod Mahesh
    Karia, Deepak C.
    2015 IEEE BOMBAY SECTION SYMPOSIUM (IBSS), 2015,
  • [9] Semantic security against web application attacks
    Razzaq, Abdul
    Latif, Khalid
    Ahmad, H. Farooq
    Hur, Ali
    Anwar, Zahid
    Bloodsworth, Peter Charles
    INFORMATION SCIENCES, 2014, 254 : 19 - 38
  • [10] Analysis and Classification of SQL Injection Vulnerabilities and Attacks on Web Applications
    Sharma, Chandershekhar
    Jain, S. C.
    2014 INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING AND TECHNOLOGY RESEARCH (ICAETR), 2014,