首页> 外文会议>SAI Computing Conference >A hybrid method for detection and prevention of SQL injection attacks
【24h】

A hybrid method for detection and prevention of SQL injection attacks

机译:检测和预防SQL注入攻击的混合方法

获取原文

摘要

SQL injection attack (SQLIA) pose a serious security threat to the database driven web applications. This kind of attack gives attackers easily access to the application's underlying database and to the potentially sensitive information these databases contain. A hacker through specifically designed input, can access content of the database that cannot otherwise be able to do so. This is usually done by altering SQL statements that are used within web applications. Due to importance of security of web applications, researchers have studied SQLIA detection and prevention extensively and have developed various methods. In this research, after reviewing the existing research in this field, we present a new hybrid method to reduce the vulnerability of the web applications. Our method is specifically designed to detect and prevent SQLIA. Our proposed method is consists of three phases namely, the database design, implementation, and at the common gateway interface (CGI). Details of our approach along with its pros and cons are discussed in detail.
机译:SQL注入攻击(SQLIA)对数据库驱动的Web应用程序构成了严重的安全威胁。这种攻击使攻击者可以轻松访问应用程序的基础数据库以及这些数据库包含的潜在敏感信息。黑客可以通过专门设计的输入来访问数据库中原本无法访问的内容。这通常是通过更改Web应用程序中使用的SQL语句来完成的。由于Web应用程序安全性的重要性,研究人员对SQLIA检测和预防进行了广泛的研究,并开发了各种方法。在本研究中,在回顾了该领域的现有研究之后,我们提出了一种新的混合方法来减少Web应用程序的漏洞。我们的方法专门设计用于检测和预防SQLIA。我们提出的方法包括三个阶段,即数据库设计,实施和公共网关接口(CGI)。详细讨论了我们的方法的优缺点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号