首页> 外文会议>Malaysian Software Engineering Conference >A component based SQL injection vulnerability detection tool
【24h】

A component based SQL injection vulnerability detection tool

机译:基于组件的SQL注入漏洞检测工具

获取原文

摘要

SQL injection attack (SQLIA) is one of the most severe attacks that can be used against web database driving applications. Attackers' use SQLIA to get unauthorized access to and perform unauthorized data modification. To mitigate the devastating problem of SQLIA, different researchers proposed variety of web penetration testing tools that automation of SQLI vulnerability assessment that result in SQLIA. Recent study shows that there is need for adaptation of object orienting approach in development of application program in order to reduce the cost of integration and maintenance, as well as improve the efficiency of application programs. Most of the proposed SQLIV (SQL injection vulnerability) detection tools by academic researchers seem to focus on improving efficiency or effectiveness of SQLIV detection tool thereby paying less attention to advantage of adopting reusable component. Therefore, this paper propose component based (CBC) SQLIV detection tool that has the potential to enable developer to reuse component where necessary and allow integration and maintenance fast and in less cost. The proposed tool was tested on three different vulnerable web applications after which its effectiveness was compared against seven(7) different SQLIV detection tool accordingly, the result of evaluation proves that the tool has all the potential to detect SQLIV vulnerabilities on different scenarios that other of scanners ware unable to detect.
机译:SQL注入攻击(SQLIA)是可用于Web数据库驱动应用程序的最严重的攻击之一。攻击者使用SQLIA来获得未经授权的访问并执行未经授权的数据修改。为了减轻SQLIA的毁灭性问题,不同的研究人员提出了各种Web渗透测试工具,这些工具可自动执行导致SQLIA的SQLI漏洞评估。最近的研究表明,在应用程序的开发中需要采用面向对象的方法,以减少集成和维护的成本,并提高应用程序的效率。学术研究人员提出的大多数SQLIV(SQL注入漏洞)检测工具似乎都集中在提高SQLIV检测工具的效率或有效性上,因此较少关注采用可重用组件的优势。因此,本文提出了基于组件(CBC)的SQLIV检测工具,该工具具有使开发人员在必要时可以重用组件并允许快速集成和维护且成本较低的潜力。该工具在三个不同的易受攻击的Web应用程序上进行了测试,然后将其有效性与七(7)个不同的SQLIV检测工具进行了比较,评估结果证明,该工具具有在其他情况下检测SQLIV漏洞的所有潜力。扫描仪软件无法检测到。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号