【24h】

A Two-Tiered Defence of Techniques to Prevent SQL Injection Attacks

机译:防止SQL注入攻击的技术防御技术

获取原文

摘要

SQL injection attacks (SQLIA) is one of the topmost threats affects business operations at present. Aho-Corasick (AC) multi-pattern matching algorithm combined with static analysis and dynamic tectonic attack mode to detect and prevent SQL injection attacks effectively. However, for the database, we can also detect and prevent SQL injection with the concept of access to database users and roles. In this paper, we analyze the existing methods of detecting and preventing SQL injection. Besides we extend the traditional AC multi-pattern matching algorithm and propose a two-tiered defence of techniques-the first tier is the fine-grained role-based access control (RBAC) model and the second tier is an extended AC multi-pattern matching algorithm, which improve the detection efficiency and reduce the SQL statement detection time.
机译:SQL注入攻击(SQLIA)是最顶层的威胁,它是目前的业务运营的最大威胁之一。 AHO-Corasick(AC)多模式匹配算法结合静态分析和动态构造攻击模式,有效检测和防止SQL注入攻击。 但是,对于数据库,我们还可以通过访问数据库用户和角色的访问概念来检测和防止SQL注入。 在本文中,我们分析了检测和预防SQL注射的现有方法。 除了我们扩展传统的AC多模式匹配算法并提出双层防御技术 - 第一层是基于微粒的角色的访问控制(RBAC)模型,第二层是扩展的AC多模式匹配 算法,提高检测效率并降低SQL语句检测时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号