首页> 外文会议>International Conference on Collaboration Technologies and Systems >Classification of Lightweight Directory Access Protocol query injection attacks and mitigation techniques
【24h】

Classification of Lightweight Directory Access Protocol query injection attacks and mitigation techniques

机译:轻量级目录访问协议查询注入攻击和缓解技术的分类

获取原文

摘要

The Lightweight Directory Access Protocol (LDAP) is used in a large number of web applications, and therefore, different types of LDAP injection attacks are becoming common. These injection attacks take advantage of an application not validating inputs before being used as part of LDAP queries. An attacker can provide inputs that may result in the alteration of intended LDAP query structure. The attacks can lead to various types of security breaches including Login Bypassing, Information Disclosure, Privilege Escalation, and Information Alteration. Despite many research efforts to prevent LDAP injection attacks, many web applications remain vulnerable to such attacks. In particular, there has been little attention given to implement and test secure web applications that can mitigate LDAP query injection attacks. More attention has been given to prevent Structured Query Language (SQL) injection attacks but these mitigation techniques cannot be directly applied in order to prevent LDAP injection attacks. This work provides analysis and classification of various types of LDAP injection attacks and mitigation techniques used to prevent them, and it highlights the differences between SQL and LDAP injection attacks.
机译:轻量级目录访问协议(LDAP)用于大量Web应用程序,因此,不同类型的LDAP注入攻击正在变得常见。这些注入攻击利用未在用作LDAP查询的一部分之前验证输入的应用程序。攻击者可以提供可能导致预期LDAP查询结构更改的输入。攻击可能导致各种类型的安全漏洞,包括登录旁路,信息披露,特权升级和信息更改。尽管有许多研究努力来防止LDAP注入攻击,但许多Web应用程序仍然容易受到这种攻击的影响。特别是,在实现和测试可以减轻LDAP查询注入攻击的安全Web应用程序的情况下几乎没有关注。已经提请更多注意防止结构化查询语言(SQL)注入攻击,但不能直接应用这些缓解技术以防止LDAP注入攻击。这项工作提供了用于防止它们的各种类型的LDAP注入攻击和缓解技术的分析和分类,它突出了SQL和LDAP注入攻击之间的差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号