عنوان المقالة:Protection Web Applications using Real-Time Technique to Detect Structured Query Language Injection Attacks
نبيل صالح علي | Nabeel Salih Ali | 9770
Publication Type
Journal
Arabic Authors
Nabeel Salih Ali, Abd Samad Shibghatullah
Abstract
At present, Web applications have been used for most of our life activities increasingly, and they affected by Structured Query Language Injection Attacks (SQLIAs). This attack is a method that attackers employ to impose the database in most of the web applications, by manipulate SQL queries, which sent to the Relational Database Management System (RDBMS). Hence, change the behavior of the applications. In This paper, developing Web Application SQLI Protector (WASP) tool in real-time web application to detect SQL injection attacks in stored procedures. Then, evaluated and analyze the developed tool respect to efficiency and effectiveness in practices. The propose technique uses realtime based on positive tainting, accurate and efficiency taint propagation, and syntax aware evaluation of the query strings at the application level to detect illegal queries before they reach at the database by using Microsoft ASP.NET. The developed tool effective due to it capable of detect and stop all SQLI attacks in real-time environment and did not generate any false negative, a few-false positive values in the results and impose minimal deploy requirements.
Publication Date
9/16/2016
Publisher
International Journal of Computer Applications
DOI
10.5120/ij
File Link
تحميل (240 مرات التحميل)
External Link
http://www.ijcaonline.org/archives/volume149/number6/ali-2016-ijca-911424.pdf
Keywords
Web applications, SQL Injection, Detection, WASP, Techniques.
رجوع