【24h】

SQL Injection: A sample review

机译:SQL注入:示例审查

获取原文

摘要

In today's world, SQL Injection is a serious security threat over the Internet for the various dynamic web applications residing over the internet. These Web applications conduct many vital processes in various web-based businesses. As the use of internet for various online services is rising, so is the security threats present in the web increasing. There is a universal need present for all dynamic web applications and this universal need is the need to store, retrieve or manipulate information from a database. Most of systems which manage the databases and its requirements such as MySQL Server and PostgreSQL use SQL as their language. Flexibility of SQL makes it a powerful language. It allows its users to ask what he/she wants without leaking any information about how the data will be fetched. However the vast use of SQL based databases has made it the center of attention of hackers. They take advantage of the poorly coded Web applications to attack the databases. They introduce an apparent SQL query, through an unauthorized user input, into the legitimate query statement. In this paper, we have tried to present a comprehensive review of all the different types of SQL injection attacks present, as well as detection of such attacks and preventive measure used. We have highlighted their individual strengths and weaknesses. Such a classification would help other researchers to choose the right technique for further studies.
机译:在当今世界,SQL注入对于驻留在Internet上的各种动态Web应用程序是Internet上的严重安全威胁。这些Web应用程序在各种基于Web的业务中执行许多重要的过程。随着各种在线服务对互联网的使用不断增加,网络中存在的安全威胁也在增加。对于所有动态Web应用程序都存在普遍需求,而这种普遍需求是需要从数据库存储,检索或操纵信息。管理数据库及其要求的大多数系统(例如MySQL Server和PostgreSQL)都使用SQL作为其语言。 SQL的灵活性使其成为一种功能强大的语言。它允许用户询问他/她想要什么,而不会泄漏有关如何获取数据的任何信息。但是,基于SQL的数据库的广泛使用已使其成为黑客关注的焦点。他们利用编码不良的Web应用程序攻击数据库。它们通过未经授权的用户输入将明显的SQL查询引入合法查询语句。在本文中,我们试图对目前存在的所有不同类型的SQL注入攻击进行全面综述,并检测此类攻击和使用的预防措施。我们已经强调了他们各自的长处和短处。这样的分类将帮助其他研究人员选择正确的技术进行进一步的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号