首页> 外文学位 >SQL Injection Vulnerability Detection Technique software during development.
【24h】

SQL Injection Vulnerability Detection Technique software during development.

机译:开发过程中的SQL注入漏洞检测技术软件。

获取原文
获取原文并翻译 | 示例

摘要

Security in software applications is the most important aspect of any information management system. Recent trends in data driven software application technologies have proven that the significance of data and its security is paramount for any application. This research presents various techniques and approaches in enforcing data security from web attacks through SQL injection. SQL injection is a technique of inserting malicious code to exploit web sites. It has become more prevalent during the recent times, but it is not taken as a serious security risk till the end of development phase. Though recent developments in web security have provided powerful strategies each one of them has its own disadvantages likes rewriting the source code or unable to detect all vulnerabilities in the web application. Hence, there is a need for a mechanism where the application code could be compiled and pitfalls detected during the development process.;This research work proposes a tool called SQL Injection Vulnerability Detection Technique (SQLIV-DT) that detects vulnerabilities in the SQL code and helps the application developers to add an additional measure of prevention during the code development process. The proposed mechanism is based on best practices in Query writing in a larger scope and it remains to be a more stable approach with fewer changes needed in implementation against a future SQL Injection types. This mechanism in real time throws warning messages for queries that are potential risks against a future SQL-Injection attack. The techniques presented in the paper apply to any data driven applications which are potentially prone to SQL injection attacks. The contribution of this research is to provide mechanisms to detect vulnerable code, thereby educating the developers of the potential risks against a future SQL injection attack.
机译:软件应用程序中的安全性是任何信息管理系统中最重要的方面。数据驱动软件应用程序技术的最新趋势已证明,数据的重要性及其安全性对于任何应用程序都是至关重要的。这项研究提出了各种技术和方法,可以通过SQL注入来增强Web攻击的数据安全性。 SQL注入是一种插入恶意代码以利用网站的技术。它在最近变得越来越普遍,但是直到开发阶段结束,它才被视为严重的安全风险。尽管Web安全的最新发展提供了强大的策略,但是每个策略都有其自身的缺点,例如重写源代码或无法检测Web应用程序中的所有漏洞。因此,需要一种可以在开发过程中编译应用程序代码并检测缺陷的机制。这项研究工作提出了一种称为SQL注入漏洞检测技术(SQLIV-DT)的工具,该工具可以检测SQL代码和帮助应用程序开发人员在代码开发过程中添加其他预防措施。所提出的机制基于更大范围内的Query编写的最佳实践,并且仍然是一种更稳定的方法,在针对将来的SQL Injection类型的实现中需要进行的更改更少。这种机制可以实时向可能引发未来SQL注入攻击风险的查询发出警告消息。本文中介绍的技术适用于任何可能容易受到SQL注入攻击的数据驱动应用程序。这项研究的目的是提供机制来检测易受攻击的代码,从而教育开发人员应对将来的SQL注入攻击的潜在风险。

著录项

  • 作者

    Raavi, Bhargavi.;

  • 作者单位

    California State University, Long Beach.;

  • 授予单位 California State University, Long Beach.;
  • 学科 Computer Science.
  • 学位 M.S.
  • 年度 2009
  • 页码 108 p.
  • 总页数 108
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号