A novel method for SQL injection attack detection based on removing SQL query attribute values

  • Lee, Inyong
  • Jeong, Soonki
  • Yeo, Sangsoo
  • Moon, Jongsub
Citations

WEB OF SCIENCE

69
Citations

SCOPUS

120

초록

SQL injection or SQL insertion attack is a code injection technique that exploits a security vulnerability occurring in the database layer of an application and a service. This is most often found within web pages with dynamic content. This paper proposes a very simple and effective detection method for SQL injection attacks. The method removes the value of an SQL query attribute of web pages when parameters are submitted and then compares it with a predetermined one. This method uses combined static and dynamic analysis. The experiments show that the proposed method is very effective and simple than any other methods. (C) 2011 Elsevier Ltd. All rights reserved.

키워드

SQL injection attackSQL queryA combined dynamic and static methodDBMSWeb application
제목
A novel method for SQL injection attack detection based on removing SQL query attribute values
저자
Lee, InyongJeong, SoonkiYeo, SangsooMoon, Jongsub
DOI
10.1016/j.mcm.2011.01.050
발행일
2012-01
유형
Article
저널명
Mathematical and Computer Modelling
55
1-2
페이지
58 ~ 68