首页> 外国专利> System, method and program product for detecting SQL queries injected into data fields of requests made to applications

System, method and program product for detecting SQL queries injected into data fields of requests made to applications

机译:用于检测注入到对应用程序的请求的数据字段中的SQL查询的系统,方法和程序产品

摘要

System, method and program product for detecting a malicious SQL query in a parameter value field of a request. The parameter value field is searched for query operands, characters and/or symbols and combinations of query operands, characters and/or symbols indicative of malicious SQL injection. A respective score assigned to each of the query operands, characters and/or symbols or combinations of query operands, characters and/or symbols found in the parameter value field is added to yield a total score for at least two of the query operands, characters and/or symbols or combinations of query operands, characters and/or symbols found in the parameter value field. Responsive to the total score exceeding a threshold, the request is blocked.
机译:用于在请求的参数值字段中检测恶意SQL查询的系统,方法和程序产品。在参数值字段中搜索指示恶意SQL注入的查询操作数,字符和/或符号以及查询操作数,字符和/或符号的组合。分配给在参数值字段中找到的每个查询操作数,字符和/或符号或查询操作数,字符和/或符号的组合的相应分数,以产生至少两个查询操作数,字符的总分数和/或符号或在参数值字段中找到的查询操作数,字符和/或符号的组合。响应总分数超过阈值,请求被阻止。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号