کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456579 695741 2009 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
SDriver: Location-specific signatures prevent SQL injection attacks
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
SDriver: Location-specific signatures prevent SQL injection attacks
چکیده انگلیسی

SQL injection attacks involve the construction of application input data that will result in the execution of malicious SQL statements. Many web applications are prone to SQL injection attacks. This paper proposes a novel methodology of preventing this kind of attacks by placing a secure database driver between the application and its underlying relational database management system. To detect an attack, the driver uses stripped-down SQL queries and stack traces to create SQL statement signatures that are then used to distinguish between injected and legitimate queries. The driver depends neither on the application nor on the RDBMS and can be easily retrofitted to any system. We have developed a tool, SDriver, that implements our technique and used it on several web applications with positive results.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 28, Issues 3–4, May–June 2009, Pages 121–129
نویسندگان
, ,