首页> 外文会议>Communication Systems and Network Technologies (CSNT), 2012 International Conference on >A Survey on Web Application Vulnerabilities (SQLIA, XSS) Exploitation and Security Engine for SQL Injection
【24h】

A Survey on Web Application Vulnerabilities (SQLIA, XSS) Exploitation and Security Engine for SQL Injection

机译:针对SQL注入的Web应用程序漏洞(SQLIA,XSS)开发和安全引擎的调查

获取原文
获取原文并翻译 | 示例

摘要

Today almost all organizations have improved their performance through allowing more information exchange within their organization as well as between their distributers, suppliers, and customers using web support. Databases are central to the modern websites as they provide necessary data as well as stores critical information such as user credentials, financial and payment information, company statistics etc. These websites have been continuously targeted by highly motivated malicious users to acquire monetary gain. Structured Query Language (SQL) injection and Cross Site Scripting Attack (XSS) is perhaps one of the most common application layer attack technique used by attacker to deface the website, manipulate or delete the content through inputting unwanted command strings. Structured Query Language Injection Attacks (SQLIA) is ranked 1st in the Open Web Application Security Project (OWASP) [1] top 10 vulnerability list and has resulted in massive attacks on a number of websites in the past few years. In this paper, we present a detailed review on various types of Structured Query Language Injection attacks, Cross Site Scripting Attack, vulnerabilities, and prevention techniques. Besides presenting our findings from the survey, we also propose future expectations and possible development of countermeasures against Structured Query Language Injection attacks.
机译:如今,几乎所有组织都通过允许在组织内部以及使用Web支持的分销商,供应商和客户之间进行更多的信息交换来提高绩效。数据库是现代网站的中心,因为它们提供必要的数据并存储关键信息,例如用户凭证,财务和付款信息,公司统计信息等。这些网站一直受到积极进取的恶意用户的攻击,以获取金钱收益。结构化查询语言(SQL)注入和跨站点脚本攻击(XSS)可能是攻击者用来破坏网站,通过输入不需要的命令字符串来操纵或删除内容的最常见的应用程序层攻击技术之一。结构化查询语言注入攻击(SQLIA)在开放式Web应用程序安全项目(OWASP)[1]十大漏洞列表中排名第一,并且在过去几年中对许多网站进行了大规模攻击。在本文中,我们对各种类型的结构化查询语言注入攻击,跨站点脚本攻击,漏洞和预防技术进行了详细介绍。除了提出调查结果外,我们还提出了对结构化查询语言注入攻击的未来期望和对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号