首页> 外文会议>2012 12th International Conference on Intelligent Systems Design and Applications. >SQLStor: Blockage of stored procedure SQL injection attack using dynamic query structure validation
【24h】

SQLStor: Blockage of stored procedure SQL injection attack using dynamic query structure validation

机译:SQLStor:使用动态查询结构验证阻止存储过程SQL注入攻击

获取原文
获取原文并翻译 | 示例

摘要

Web applications are becoming an important part of our daily life. So attacks against them also increases rapidly. Of these attacks, a major role is held by SQL injection attacks (SQLIA). This paper proposes a new method for preventing SQL injection attacks in JSP web applications. The basic idea is to check before execution, the intended structure of the SQL query. For this we use semantic comparison. This method prevents different kinds of injection attacks including stored procedure attack which is more difficult and less considered in the literature.
机译:Web应用程序正在成为我们日常生活的重要组成部分。因此,针对他们的攻击也迅速增加。在这些攻击中,SQL注入攻击(SQLIA)扮演着主要角色。本文提出了一种防止JSP Web应用程序中SQL注入攻击的新方法。基本思想是在执行之前检查SQL查询的预期结构。为此,我们使用语义比较。这种方法可以防止各种类型的注入攻击,包括存储过程攻击,这在文献中更为困难且较少考虑。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号