首页> 外文会议>International Conference on Communication Systems and Network Technologies >A Survey on Web Application Vulnerabilities (SQLIA, XSS) Exploitation and Security Engine for SQL Injection
【24h】

A Survey on Web Application Vulnerabilities (SQLIA, XSS) Exploitation and Security Engine for SQL Injection

机译:用于SQL注入的Web应用程序漏洞(SQLIA,XSS)开发和安全引擎的调查

获取原文

摘要

Today almost all organizations have improved their performance through allowing more information exchange within their organization as well as between their distributers, suppliers, and customers using web support. Databases are central to the modern websites as they provide necessary data as well as stores critical information such as user credentials, financial and payment information, company statistics etc. These websites have been continuously targeted by highly motivated malicious users to acquire monetary gain. Structured Query Language (SQL) injection and Cross Site Scripting Attack (XSS) is perhaps one of the most common application layer attack technique used by attacker to deface the website, manipulate or delete the content through inputting unwanted command strings. Structured Query Language Injection Attacks (SQLIA) is ranked 1st in the Open Web Application Security Project (OWASP) [1] top 10 vulnerability list and has resulted in massive attacks on a number of websites in the past few years. In this paper, we present a detailed review on various types of Structured Query Language Injection attacks, Cross Site Scripting Attack, vulnerabilities, and prevention techniques. Besides presenting our findings from the survey, we also propose future expectations and possible development of countermeasures against Structured Query Language Injection attacks.
机译:今天,几乎所有组织都通过允许其组织内的更多信息交流以及他们的分销商,供应商和客户使用Web支持来提高表现。数据库是现代网站的核心,因为它们提供必要的数据以及商店的关键信息,如用户凭据,财务和付款信息,公司统计数据等。这些网站被高度激励的恶意用户持续针对货币增益。结构化查询语言(SQL)注入和跨站点脚本攻击(XSS)可能是攻击者使用的最常见的应用程序层攻击技术之一,以通过输入不需要的命令字符串来操作或删除内容。结构化查询语言注入攻击(SQLIA)在Open Web应用程序安全项目(OWASP)[1]中排名第1页,其中十大漏洞列表,并导致过去几年的许多网站攻击。在本文中,我们对各类结构化查询语言注入攻击,跨站点脚本攻击,漏洞和预防技术进行了详细审查。除了从调查中介绍我们的调查结果,我们还提出了未来的期望和可能的对抗结构查询语言注射攻击的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号