首页> 外文会议>Advance Computing Conference,IACC,2009 IEEE International >Combinatorial Approach for Preventing SQL Injection Attacks
【24h】

Combinatorial Approach for Preventing SQL Injection Attacks

机译:防止SQL注入攻击的组合方法

获取原文

摘要

A combinatorial approach for protecting Web applications against SQL injection is discussed in this paper, which is a novel idea of incorporating the uniqueness of Signature based method and auditing method. The major issue of web application security is the SQL Injection, which can give the attackers unrestricted access to the database that underlie Web applications and has become increasingly frequent and serious. From signature based method standpoint of view, it present a detection mode for SQL injection using pair wise sequence alignment of amino acid code formulated from wab application form parameter sent via web server. On the other hand from the Auditing based method standpoint of view, it analyzes the transaction to find out the malicious access. In signature based method It uses an approach called Hirschberg algorithm, it is a divide and conquer approach to reduce the time and space complexity. This system was able to stop all of the successful attacks and did not generate any false positives.
机译:本文讨论了一种保护Web应用程序免受SQL注入攻击的组合方法,这是一种结合了基于签名的方法和审计方法的唯一性的新颖思想。 Web应用程序安全性的主要问题是SQL注入,它可以使攻击者不受限制地访问Web应用程序基础的数据库,并且数据库变得越来越频繁和严重。从基于签名的方法的角度来看,它提出了一种使用SQL注入的检测模式,该方法是使用通过Web服务器发送的WAB应用程序形式参数制定的氨基酸代码的成对序列比对来实现的。另一方面,从基于审计的方法的角度来看,它分析事务以找出恶意访问。在基于签名的方法中,它使用一种称为Hirschberg算法的方法,它是一种分治法,可以减少时间和空间的复杂性。该系统能够阻止所有成功的攻击,并且不会产生任何误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号