首页> 外文会议>IEEE Symposium on Computer Applications and Industrial Electronics >Detection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack
【24h】

Detection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack

机译:SQL注入攻击的检测模型:一种防止Web应用程序受到SQL注入攻击的方法

获取原文

摘要

Since the past 20 years the uses of web in daily life is increasing and becoming trend now. As the use of the web is increasing, the use of web application is also increasing. Apparently most of the web application exists up to today have some vulnerability that could be exploited by unauthorized person. Some of well-known web application vulnerabilities are Structured Query Language (SQL) Injection, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). By compromising with these web application vulnerabilities, the system cracker can gain information about the user and lead to the reputation of the respective organization. Usually the developers of web applications did not realize that their web applications have vulnerabilities. They only realize them when there is an attack or manipulation of their code by someone. This is normal as in a web application, there are thousands of lines of code, therefore it is not easy to detect if there are some loopholes. Nowadays as the hacking tools and hacking tutorials are easier to get, lots of new hackers are born. Even though SQL injection is very easy to protect against, there are still large numbers of the system on the internet are vulnerable to this type of attack because there will be a few subtle condition that can go undetected. Therefore, in this paper we propose a detection model for detecting and recognizing the web vulnerability which is; SQL Injection based on the defined and identified criteria. In addition, the proposed detection model will be able to generate a report regarding the vulnerability level of the web application. As the consequence, the proposed detection model should be able to decrease the possibility of the SQL Injection attack that can be launch onto the web application.
机译:在过去的20年中,网络在日常生活中的使用正在增加,并且现在已成为趋势。随着网络的使用增加,网络应用程序的使用也增加。显然,迄今为止,大多数Web应用程序都存在一些未经授权的人可以利用的漏洞。一些著名的Web应用程序漏洞是结构化查询语言(SQL)注入,跨站点脚本(XSS)和跨站点请求伪造(CSRF)。通过破坏这些Web应用程序的漏洞,系统破解者可以获得与用户有关的信息,并获得相应组织的声誉。通常,Web应用程序的开发人员没有意识到他们的Web应用程序具有漏洞。他们只有在有人攻击或操纵其代码时才意识到它们。这是正常的,因为在Web应用程序中,有成千上万的代码行,因此,不容易发现是否存在漏洞。如今,由于更容易获得黑客工具和黑客教程,因此诞生了许多新的黑客。尽管SQL注入非常容易防范,但是Internet上仍有大量系统容易受到这种类型的攻击,因为会有一些微妙的情况无法发现。因此,在本文中,我们提出了一种用于检测和识别Web漏洞的检测模型。基于定义和识别的条件的SQL注入。此外,建议的检测模型将能够生成有关Web应用程序漏洞级别的报告。因此,建议的检测模型应该能够减少可能会在Web应用程序上发起的SQL Injection攻击的可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号