A novel method for SQL injection attack detection based on removing SQL query attribute values
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Lee, Inyong | - |
dc.contributor.author | Jeong, Soonki | - |
dc.contributor.author | Yeo, Sangsoo | - |
dc.contributor.author | Moon, Jongsub | - |
dc.date.accessioned | 2021-09-06T23:28:07Z | - |
dc.date.available | 2021-09-06T23:28:07Z | - |
dc.date.created | 2021-06-18 | - |
dc.date.issued | 2012-01 | - |
dc.identifier.issn | 0895-7177 | - |
dc.identifier.uri | https://scholar.korea.ac.kr/handle/2021.sw.korea/109184 | - |
dc.description.abstract | SQL injection or SQL insertion attack is a code injection technique that exploits a security vulnerability occurring in the database layer of an application and a service. This is most often found within web pages with dynamic content. This paper proposes a very simple and effective detection method for SQL injection attacks. The method removes the value of an SQL query attribute of web pages when parameters are submitted and then compares it with a predetermined one. This method uses combined static and dynamic analysis. The experiments show that the proposed method is very effective and simple than any other methods. (C) 2011 Elsevier Ltd. All rights reserved. | - |
dc.language | English | - |
dc.language.iso | en | - |
dc.publisher | PERGAMON-ELSEVIER SCIENCE LTD | - |
dc.title | A novel method for SQL injection attack detection based on removing SQL query attribute values | - |
dc.type | Article | - |
dc.contributor.affiliatedAuthor | Moon, Jongsub | - |
dc.identifier.doi | 10.1016/j.mcm.2011.01.050 | - |
dc.identifier.scopusid | 2-s2.0-82755194883 | - |
dc.identifier.wosid | 000296919500008 | - |
dc.identifier.bibliographicCitation | MATHEMATICAL AND COMPUTER MODELLING, v.55, no.1-2, pp.58 - 68 | - |
dc.relation.isPartOf | MATHEMATICAL AND COMPUTER MODELLING | - |
dc.citation.title | MATHEMATICAL AND COMPUTER MODELLING | - |
dc.citation.volume | 55 | - |
dc.citation.number | 1-2 | - |
dc.citation.startPage | 58 | - |
dc.citation.endPage | 68 | - |
dc.type.rims | ART | - |
dc.type.docType | Article | - |
dc.description.journalClass | 1 | - |
dc.description.journalRegisteredClass | scie | - |
dc.description.journalRegisteredClass | scopus | - |
dc.relation.journalResearchArea | Computer Science | - |
dc.relation.journalResearchArea | Mathematics | - |
dc.relation.journalWebOfScienceCategory | Computer Science, Interdisciplinary Applications | - |
dc.relation.journalWebOfScienceCategory | Computer Science, Software Engineering | - |
dc.relation.journalWebOfScienceCategory | Mathematics, Applied | - |
dc.subject.keywordAuthor | SQL injection attack | - |
dc.subject.keywordAuthor | SQL query | - |
dc.subject.keywordAuthor | A combined dynamic and static method | - |
dc.subject.keywordAuthor | DBMS | - |
dc.subject.keywordAuthor | Web application | - |
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.
(02841) 서울특별시 성북구 안암로 14502-3290-1114
COPYRIGHT © 2021 Korea University. All Rights Reserved.
Certain data included herein are derived from the © Web of Science of Clarivate Analytics. All rights reserved.
You may not copy or re-distribute this material in whole or in part without the prior written consent of Clarivate Analytics.