A Security Analysis Tool For Web Application Reinforcement Against SQL Injection Attacks (SQLIAs)

被引:0
|
作者
Lashkaripour, Z. [1 ]
Bafghi, A. Ghaemi [1 ]
机构
[1] Ferdowsi Univ Mashhad, Dept Comp, Data & Commun Secur Lab, Fac Engn, Mashhad, Iran
来源
2013 10TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC) | 2013年
关键词
Web application; SQLIA; transformation; static analysis; detection;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In SQLIA, attacker injects an input in the query in order to change the structure of the query intended by the programmer and therefore, gain access to the data in the underlying database. Due to the significance of the stored data, web application's security against SQLIA is vital. In this paper we propose a tool that is capable of reporting the transformations needed to reinforce the security of a Java-based web application and its database against SQLIAs. This tool which is based on static analysis and runtime validation uses our new technique for detection and prevention of SQLIAs. In our technique user inputs in SQL queries are removed and some information is gathered in order to make the detection easier and faster at runtime. According to these information the tool reports the transformations needed and the location of the transformations in source code and therefore after applying the transformations the result would be a reinforced web application against SQLIAs.
引用
收藏
页数:8
相关论文
共 34 条
  • [21] Enhancing Java']Java Web Application Security: Injection Vulnerability Detection via Interprocedural Analysis and Deep Learning
    Zhang, Bing
    Zhi, Xu
    Wang, Meng
    Ren, Rong
    Dong, Jun
    IEEE TRANSACTIONS ON RELIABILITY, 2025,
  • [22] Evaluation of Black-Box Web Application Security Scanners in Detecting Injection Vulnerabilities
    Althunayyan, Muzun
    Saxena, Neetesh
    Li, Shancang
    Gope, Prosanta
    ELECTRONICS, 2022, 11 (13)
  • [23] Semantic web Racer: Dynamic security testing of the web application against race condition in the business layer
    Alidoosti, Mitra
    Nowroozi, Alireza
    Nickabadi, Ahmad
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 195
  • [24] Design and Security Analysis of web application based and web services based Patient Management System (PMS)
    Rajput, Sahil
    Vadivel, S.
    Shetty, Sujala D.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (03): : 22 - 28
  • [25] 1-AID: A Web Application Tool for First Aid and Homeopathic Treatment with Vulnerability Security Scanning
    Samonte, Mary Jane C.
    Laraze, Patricia Ann D.
    Nisperos, Bryelle Timothy C.
    Sandoval, Jaryl V.
    2022 12TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGY AND ENGINEERING, ICSTE, 2022, : 40 - 45
  • [26] A Survey and Vital Analysis of Various State of the Art Solutions for Web Application Security
    Thankachan, Anna
    Ramakrishnan, R.
    Kalaiarasi, M.
    2014 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2014,
  • [27] An Integrated Approach for Effective Injection Vulnerability Analysis of Web Applications Through Security Slicing and Hybrid Constraint Solving
    Thome, Julian
    Shar, Lwin Khin
    Bianculli, Domenico
    Briand, Lionel
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2020, 46 (02) : 163 - 195
  • [28] System evaluation and meta-analysis of Web application security vulnerabilities under black-box genetic algorithm
    Hao, XuanYi
    REVIEWS OF ADHESION AND ADHESIVES, 2023, 11 (02): : 20 - 38
  • [29] CBE Clima Tool: A free and open-source web application for climate analysis tailored to sustainable building design
    Giovanni Betti
    Federico Tartarini
    Christine Nguyen
    Stefano Schiavon
    Building Simulation, 2024, 17 : 493 - 508
  • [30] CBE Clima Tool: A free and open-source web application for climate analysis tailored to sustainable building design
    Betti, Giovanni
    Tartarini, Federico
    Nguyen, Christine
    Schiavon, Stefano
    BUILDING SIMULATION, 2024, 17 (03) : 493 - 508