首页> 外文会议>Recent Advances in Information Technology (RAIT), 2012 1st International Conference on >A network based vulnerability scanner for detecting SQLI attacks in web applications
【24h】

A network based vulnerability scanner for detecting SQLI attacks in web applications

机译:基于网络的漏洞扫描程序,用于检测Web应用程序中的SQLI攻击

获取原文
获取原文并翻译 | 示例

摘要

Today is the world of information era, where information is available on just our single click. Web applications are playing a magnificent role in this, every organizations are mapping their business from a room to the world with the help of these Web Apps. Web applications generally consist of a three tier architecture where database is in the third pole, which is the most valuable assets in any organization, as the adaptation of web applications are increases day by day, various attacks are possible against this. SQL injection is an attack in which an attacker directly compromises the database, that's why this is a most threatening attack. Various Vulnerability scanners has been proposed to deal with this, but none of them are able to detect SQLI completely, the existing tools have the accuracy ratio very less as well as they produce a high rate of false positive, apart from that all these tools take much time to scan. So here we are presenting a network based vulnerability scanner approach which provides a better coverage and with no false positive within a short span of time.
机译:今天是信息时代,只需单击一下即可获得信息。 Web应用程序在其中起着举足轻重的作用,每个组织都借助这些Web Apps将其业务从一个房间映射到世界。 Web应用程序通常由三层体系结构组成,其中数据库处于第三极,这是任何组织中最有价值的资产,因为Web应用程序的适应性日益增加,因此可能会遭受各种攻击。 SQL注入是一种攻击者直接攻击数据库的攻击,因此这是威胁最大的攻击。已经提出了各种漏洞扫描程序来解决此问题,但是它们都不能够完全检测到SQLI,现有工具的准确率非常低,而且会产生很高的误报率,此外所有这些工具都需要扫描时间很多。因此,在此我们介绍一种基于网络的漏洞扫描程序,该方法可提供更好的覆盖范围,并且在短时间内不会出现误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号