کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
1136465 1489150 2012 11 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A novel method for SQL injection attack detection based on removing SQL query attribute values
موضوعات مرتبط
مهندسی و علوم پایه سایر رشته های مهندسی کنترل و سیستم های مهندسی
پیش نمایش صفحه اول مقاله
A novel method for SQL injection attack detection based on removing SQL query attribute values
چکیده انگلیسی

SQL injection or SQL insertion attack is a code injection technique that exploits a security vulnerability occurring in the database layer of an application and a service. This is most often found within web pages with dynamic content. This paper proposes a very simple and effective detection method for SQL injection attacks. The method removes the value of an SQL query attribute of web pages when parameters are submitted and then compares it with a predetermined one. This method uses combined static and dynamic analysis. The experiments show that the proposed method is very effective and simple than any other methods.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Mathematical and Computer Modelling - Volume 55, Issues 1–2, January 2012, Pages 58–68
نویسندگان
, , , ,