作者
Sangita Roy, Avinash Kumar Singh, Ashok Singh Sairam
发表日期
2011/7/1
期刊
International Journal of Information and Electronics Engineering
卷号
1
期号
1
页码范围
38
出版商
IACSIT Press
简介
The increasing dependence on web applications have made them a natural target for attackers. Among these attacks SQL Injection Attacks (SQLIA) are the most prevalent. In this paper we propose a SQL injection vulnerability scanner that is light-weight, fast and has a low false positive rate. These scanners prove as a practical tool to discover the vulnerabilities in a web application as well as to test the efficiency of counter attack mechanisms. In the latter part of our work we propose a security mechanism to counter SQL Injection Attacks. Our security methodology is based on the design of a filter for the HTTP request send by clients or users and look for attack signatures. The proposed filter is generic in the sense that it can be used with any web application. Finally we test our proposed security mechanism using the vulnerability scanner developed by us as well as other well known scanners. The proposed security mechanism is able to counter all the vulnerabilities that were previously reported before the deployment of our security framework.
引用总数
2014201520162017201820192020202120222023202413124511113
学术搜索中的文章
S Roy, AK Singh, AS Sairam - International Journal of Information and Electronics …, 2011