作者
Sangita Roy, Avinash Kumar Singh, Ashok Singh Sairam
发表日期
2011/5/28
期刊
Proceedings of International Conference on Information and Electronics Engineering (ICIEE 2011)
简介
SQL injection attacks (SQLIA) are widely used in which an attacker crafts input to the application server to access or modify data on the database server. A common approach for an attacker to launch SQLIA is by modifying the input URL to contain partial SQL queries and trick the server into executing them. In this paper we first identify all those input patterns that can appear in the URL of an attack. Next we proposed to deploy a SQL Meta character filter that parses the input URL to detect attack patterns. The attack patterns are so chosen so that SQL Meta characters that appear in a legal input are not filtered out. We implement the filter using Java servlet and demonstrate its effectiveness.
引用总数
2011201220132014201520161251
学术搜索中的文章
S Roy, AK Singh, AS Sairam - … of International Conference on Information and …, 2011