首页> 外文会议>IEEE International Symposium on Computer Applications and Industrial Electronics >Detection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack
【24h】

Detection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack

机译:SQL注入攻击的检测模型:防止SQL注入攻击的Web应用方法

获取原文

摘要

Since the past 20 years the uses of web in daily life is increasing and becoming trend now. As the use of the web is increasing, the use of web application is also increasing. Apparently most of the web application exists up to today have some vulnerability that could be exploited by unauthorized person. Some of well-known web application vulnerabilities are Structured Query Language (SQL) Injection, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). By compromising with these web application vulnerabilities, the system cracker can gain information about the user and lead to the reputation of the respective organization. Usually the developers of web applications did not realize that their web applications have vulnerabilities. They only realize them when there is an attack or manipulation of their code by someone. This is normal as in a web application, there are thousands of lines of code, therefore it is not easy to detect if there are some loopholes. Nowadays as the hacking tools and hacking tutorials are easier to get, lots of new hackers are born. Even though SQL injection is very easy to protect against, there are still large numbers of the system on the internet are vulnerable to this type of attack because there will be a few subtle condition that can go undetected. Therefore, in this paper we propose a detection model for detecting and recognizing the web vulnerability which is; SQL Injection based on the defined and identified criteria. In addition, the proposed detection model will be able to generate a report regarding the vulnerability level of the web application. As the consequence, the proposed detection model should be able to decrease the possibility of the SQL Injection attack that can be launch onto the web application.
机译:自过去的20年以来,网络在日常生活中的用途正在增加,现在变得越来越趋势。随着Web的使用正在增加,Web应用程序的使用也在增加。显然大多数Web应用程序都存在于今天的一些漏洞,这些漏洞可以由未经授权的人开发。一些众所周知的Web应用程序漏洞是结构性查询语言(SQL)注射,跨站点脚本(XS)和跨站点请求伪造(CSRF)。通过损害这些Web应用程序漏洞,系统饼干可以获得有关用户的信息并导致各个组织的声誉。通常,Web应用程序的开发人员没有意识到其Web应用程序具有漏洞。当某人攻击或操纵他们的代码时,他们只意识到它们。这正常如在Web应用程序中,有数千行代码,因此不容易检测有一些漏洞。如今,随着黑客工具和黑客教程更容易得到,很多新的黑客诞生了。尽管SQL注入非常容易防止,但仍有大量的互联网系统易受这种类型的攻击攻击,因为会有一些可以未被发现的微妙条件。因此,在本文中,我们提出了一种用于检测和识别Web漏洞的检测模型; SQL注入基于定义和识别的标准。此外,所提出的检测模型将能够生成关于Web应用程序漏洞级别的报告。结果,所提出的检测模型应该能够降低可以在Web应用程序上启动的SQL注入攻击的可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号