Automatic Whitelist Generation for SQL Queries Using Web Application Tests

被引:0
|
作者
Nomura, Komei [1 ]
Rikitake, Kenji [1 ,2 ]
Matsumoto, Ryosuke [3 ]
机构
[1] GMO Pepabo Inc, Pepabo R&D Inst, Tokyo, Japan
[2] KRPEO, Tokyo, Japan
[3] SAKURA Internet Inc, SAKURA Res Ctr, Osaka, Japan
关键词
D O I
10.1109/COMPSAC.2019.10250
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Stealing confidential information from a database has become a severe vulnerability issue for web applications. The attacks can be prevented by defining a whitelist of SQL queries issued by web applications and detecting queries not in list. For large-scale web applications, automated generation of the whitelist is conducted because manually defining numerous query patterns is impractical for developers. Conventional methods for automated generation are unable to detect attacks immediately because of the long time required for collecting legitimate queries. Moreover, they require application-specific implementations that reduce the versatility of the methods. As described herein, we propose a method to generate a whitelist automatically using queries issued during web application tests. Our proposed method uses the queries generated during application tests. It is independent of specific applications, which yields improved timeliness against attacks and versatility for multiple applications.
引用
收藏
页码:465 / 470
页数:6
相关论文
共 50 条
  • [1] Automatic Generation of SQL Queries
    Do, Quan
    Agrawal, Rajeev K.
    Rao, Dhana
    Gudivada, Venkat N.
    2014 ASEE ANNUAL CONFERENCE, 2014,
  • [2] Answering complex SQL queries using automatic summary tables
    Zaharioudakis, M
    Cochrane, R
    Lapis, G
    Pirahesh, H
    Urata, M
    SIGMOD RECORD, 2000, 29 (02) : 105 - 116
  • [3] Data generation for testing and grading SQL queries
    Bikash Chandra
    Bhupesh Chawda
    Biplab Kar
    K. V. Maheshwara Reddy
    Shetal Shah
    S. Sudarshan
    The VLDB Journal, 2015, 24 : 731 - 755
  • [4] Data generation for testing and grading SQL queries
    Chandra, Bikash
    Chawda, Bhupesh
    Kar, Biplab
    Reddy, K. V. Maheshwara
    Shah, Shetal
    Sudarshan, S.
    VLDB JOURNAL, 2015, 24 (06): : 731 - 755
  • [5] Inferring SQL Queries Using Interactivity
    Ahkouk, Karamwh
    Machkour, Mustapha
    antari, Jilali
    3RD INTERNATIONAL CONFERENCE ON NETWORKING, INFORMATION SYSTEM & SECURITY (NISS'20), 2020,
  • [6] BlackMagic: Automatic Inlining of Scalar UDFs into SQL Queries with Froid
    Ramachandra, Karthik
    Park, Kwanghyun
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2019, 12 (12): : 1810 - 1813
  • [7] Automatic Examination-Based Whitelist Generation for XSS Attack Detection
    Inoue, Keisuke
    Honda, Toshiki
    Mukaiyama, Kohei
    Ohki, Tetsushi
    Nishigaki, Masakatsu
    ADVANCES ON BROADBAND AND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS, BWCCA-2018, 2019, 25 : 326 - 338
  • [8] Automatic whitelist generation system for ethernet based in-vehicle network
    Jo, Wooyeon
    Kim, SungJin
    Kim, Hyunjin
    Shin, Yeonghun
    Shon, Taeshik
    COMPUTERS IN INDUSTRY, 2022, 142
  • [9] CRAXweb: Automatic Web Application Testing and Attack Generation
    Huang, Shih-Kun
    Lu, Han-Lin
    Leong, Wai-Meng
    Liu, Huan
    2013 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (SERE), 2013, : 208 - 217
  • [10] SQL Autograder: Web-based LLM-powered Autograder for Assessment of SQL Queries
    Manikani, Karan
    Chapaneri, Radhika
    Shetty, Dharmik
    Shah, Divyata
    INTERNATIONAL JOURNAL OF ARTIFICIAL INTELLIGENCE IN EDUCATION, 2025,