Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

A novel method for SQL injection attack detection based on removing SQL query attribute values

Full metadata record
DC Field Value Language
dc.contributor.authorLee, Inyong-
dc.contributor.authorJeong, Soonki-
dc.contributor.authorYeo, Sangsoo-
dc.contributor.authorMoon, Jongsub-
dc.date.accessioned2021-09-06T23:28:07Z-
dc.date.available2021-09-06T23:28:07Z-
dc.date.created2021-06-18-
dc.date.issued2012-01-
dc.identifier.issn0895-7177-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/109184-
dc.description.abstractSQL injection or SQL insertion attack is a code injection technique that exploits a security vulnerability occurring in the database layer of an application and a service. This is most often found within web pages with dynamic content. This paper proposes a very simple and effective detection method for SQL injection attacks. The method removes the value of an SQL query attribute of web pages when parameters are submitted and then compares it with a predetermined one. This method uses combined static and dynamic analysis. The experiments show that the proposed method is very effective and simple than any other methods. (C) 2011 Elsevier Ltd. All rights reserved.-
dc.languageEnglish-
dc.language.isoen-
dc.publisherPERGAMON-ELSEVIER SCIENCE LTD-
dc.titleA novel method for SQL injection attack detection based on removing SQL query attribute values-
dc.typeArticle-
dc.contributor.affiliatedAuthorMoon, Jongsub-
dc.identifier.doi10.1016/j.mcm.2011.01.050-
dc.identifier.scopusid2-s2.0-82755194883-
dc.identifier.wosid000296919500008-
dc.identifier.bibliographicCitationMATHEMATICAL AND COMPUTER MODELLING, v.55, no.1-2, pp.58 - 68-
dc.relation.isPartOfMATHEMATICAL AND COMPUTER MODELLING-
dc.citation.titleMATHEMATICAL AND COMPUTER MODELLING-
dc.citation.volume55-
dc.citation.number1-2-
dc.citation.startPage58-
dc.citation.endPage68-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalResearchAreaMathematics-
dc.relation.journalWebOfScienceCategoryComputer Science, Interdisciplinary Applications-
dc.relation.journalWebOfScienceCategoryComputer Science, Software Engineering-
dc.relation.journalWebOfScienceCategoryMathematics, Applied-
dc.subject.keywordAuthorSQL injection attack-
dc.subject.keywordAuthorSQL query-
dc.subject.keywordAuthorA combined dynamic and static method-
dc.subject.keywordAuthorDBMS-
dc.subject.keywordAuthorWeb application-
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Science and Technology > Department of Electronics and Information Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE