首页> 外文期刊>International journal of information security and privacy >Intrusion Detection Systems for Mitigating SQL Injection Attacks: Review and State-of-Practice
【24h】

Intrusion Detection Systems for Mitigating SQL Injection Attacks: Review and State-of-Practice

机译:缓解SQL注入攻击的入侵检测系统:回顾和实践状态

获取原文
获取原文并翻译 | 示例
           

摘要

Databases are widely used by organizations to store business-critical information, which makes them one of the most attractive targets for security attacks. SQL Injection is the most common attack to webpages with dynamic content. To mitigate it, organizations use Intrusion Detection Systems (IDS) as part of the security infrastructure, to detect this type of attack. However, the authors observe a gap between the comprehensive state-of-the-art in detecting SQL Injection attacks and the state-of-practice regarding existing tools capable of detecting such attacks. The majority of IDS implementations provide little or no protection against SQL Injection attacks, with exceptions like the tools Bro and ModSecurity. In this article, the authors compare these tools using the CSIC dataset in order to examine the state-of-practice in database protection from SQL Injection attacks, identifying the main characteristics and implementation details needed for IDS s to successfully detect such attacks. The experiments indicate that signature-based IDS provide the greatest coverage against SQL Injection.
机译:组织广泛使用数据库来存储业务关键信息,这使数据库成为安全攻击最有吸引力的目标之一。 SQL注入是对具有动态内容的网页的最常见攻击。为了缓解这种情况,组织使用入侵检测系统(IDS)作为安全基础结构的一部分来检测这种类型的攻击。但是,作者发现,在检测SQL注入攻击的综合性最新技术与有关能够检测此类攻击的现有工具的实践状态之间存在差距。除工具Bro和ModSecurity之类的例外外,大多数IDS实施都很少或根本没有针对SQL注入攻击的保护措施。在本文中,作者使用CSIC数据集对这些工具进行了比较,以检查数据库保护免受SQL注入攻击的实践状态,确定IDS成功检测此类攻击所需的主要特征和实现细节。实验表明,基于签名的IDS可以最大程度地防止SQL注入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号