首页> 外文会议>International Conference on Computing, Communication, Control and Automation >Analysis of web application security mechanism and Attack Detection using Vulnerability injection technique
【24h】

Analysis of web application security mechanism and Attack Detection using Vulnerability injection technique

机译:Web应用程序安全机制分析和使用漏洞注入技术的攻击检测

获取原文

摘要

The internet is growing rapidly and interconnected different wired and wireless networks with each other. By using a client server architecture computing devices which are located at different geographical locations all around the world connect to the World Wide Web. Client can access information from the web server through the web browser. Web server fetches data from the database server. Malicious minds all over the world break down the security of the data driven web applications and illegally access some private data, manipulate data or perform different malicious activities which may lead to great damage or financial loss. SQL injection attack and Denial-of-service (DOS) attack are two most important security threads found in the web applications. SQL injection is a one of the web application security vulnerability in which SQL statements are altered by attackers which is executed by the web application and submitted to the database server. DOS attack is an attack which makes network resources unavailable to its intended users. In this paper, we propose a method for evaluation of the current security mechanism by injecting vulnerabilities in the web application and exploit them using Distributed Vulnerability and Attack Detection Tool (DVADT).
机译:互联网正在迅速发展,并将不同的有线和无线网络相互连接。通过使用客户端服务器架构,位于世界各地不同地理位置的计算设备可以连接到万维网。客户端可以通过Web浏览器从Web服务器访问信息。 Web服务器从数据库服务器获取数据。全世界的恶意人士都破坏了数据驱动的Web应用程序的安全性,并非法访问了一些私人数据,操纵数据或执行各种恶意活动,这可能导致巨大的损失或财务损失。 SQL注入攻击和拒绝服务(DOS)攻击是Web应用程序中最重要的两个安全线程。 SQL注入是Web应用程序安全漏洞之一,攻击者在其中更改SQL语句,攻击者通过Web应用程序执行该SQL语句并将其提交给数据库服务器。 DOS攻击是一种攻击,它使目标用户无法使用网络资源。在本文中,我们提出了一种通过在Web应用程序中注入漏洞来评估当前安全机制的方法,并使用分布式漏洞和攻击检测工具(DVADT)对其进行利用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号