Automatic Whitelist Generation for SQL Queries Using Web Application Tests

被引:0
|
作者
Nomura, Komei [1 ]
Rikitake, Kenji [1 ,2 ]
Matsumoto, Ryosuke [3 ]
机构
[1] GMO Pepabo Inc, Pepabo R&D Inst, Tokyo, Japan
[2] KRPEO, Tokyo, Japan
[3] SAKURA Internet Inc, SAKURA Res Ctr, Osaka, Japan
关键词
D O I
10.1109/COMPSAC.2019.10250
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Stealing confidential information from a database has become a severe vulnerability issue for web applications. The attacks can be prevented by defining a whitelist of SQL queries issued by web applications and detecting queries not in list. For large-scale web applications, automated generation of the whitelist is conducted because manually defining numerous query patterns is impractical for developers. Conventional methods for automated generation are unable to detect attacks immediately because of the long time required for collecting legitimate queries. Moreover, they require application-specific implementations that reduce the versatility of the methods. As described herein, we propose a method to generate a whitelist automatically using queries issued during web application tests. Our proposed method uses the queries generated during application tests. It is independent of specific applications, which yields improved timeliness against attacks and versatility for multiple applications.
引用
收藏
页码:465 / 470
页数:6
相关论文
共 50 条
  • [21] Using contracts and boolean queries to improve the quality of automatic test generation
    Liu, Lisa
    Meyer, Bertrand
    Schoeller, Bernd
    TESTS AND PROOFS, 2007, 4454 : 114 - +
  • [22] Automatic classification of Web queries using very large unlabeled query logs
    Beitzel, Steven M.
    Jensen, Eric C.
    Lewis, David D.
    Chowdhury, Abdur
    Frieder, Ophir
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2007, 25 (02)
  • [23] Preventing SQL injection attacks by automatic parameterizing of raw queries using lexical and semantic analysis methods
    Samarin, S. Dolatnezhad
    Amini, M.
    SCIENTIA IRANICA, 2019, 26 (06) : 3469 - 3484
  • [24] AUTOMATIC GENERATION OF UML-BASED WEB APPLICATION PROTOTYPES
    Ogata, Shinpei
    Matsuura, Saeko
    ICEIS 2008: PROCEEDINGS OF THE TENTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL ISAS-1: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, VOL 1, 2008, : 244 - +
  • [25] Process-oriented web application automatic generation code
    Guido, Anna Lisa
    Paiano, Roberto
    Pandurino, Andrea
    WMSCI 2007: 11TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL I, PROCEEDINGS, 2007, : 285 - 289
  • [26] Tests Generation Oriented Web-Based Automatic Assessment of Programming Assignments
    Le Ru, Yann
    Aron, Michael
    Gerval, Jean-Pierre
    Napoleon, Thibault
    SMART EDUCATION AND SMART E-LEARNING, 2015, 41 : 117 - 127
  • [27] Question Generation from SQL Queries Improves Neural Semantic Parsing
    Guo, Daya
    Sun, Yibo
    Tang, Duyu
    Duan, Nan
    Yin, Jian
    Chi, Hong
    Cao, James
    Chen, Peng
    Zhou, Ming
    2018 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING (EMNLP 2018), 2018, : 1597 - 1607
  • [28] Structured Whitelist Generation in SCADA Network using PrefixSpan Algorithm
    Jung, Woo-Suk
    Yun, Jeong-Han
    Kim, Sin-Kyu
    Shim, Kyu-Seok
    Kim, Myung-Sup
    2017 19TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2017): MANAGING A WORLD OF THINGS, 2017, : 326 - 329
  • [29] SLocator: Localizing the Origin of SQL Queries in Database-Backed Web Applications
    Liu, Wei
    Chen, Tse-Hsun
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2023, 49 (06) : 3376 - 3390
  • [30] Towards an Automatic Generation of Low-Interaction Web Application Honeypots
    Musch, Marius
    Harterich, Martin
    Johns, Martin
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,