Defeating SQL injection attack in authentication security: an experimental study

被引:4
作者
Das, Debasish [1 ]
Sharma, Utpal [1 ]
Bhattacharyya, D. K. [1 ]
机构
[1] Tezpur Univ, Dept Comp Sci & Engn, Tezpur, India
关键词
Web-application; SQL injection; Naive Bayes; SVM; Tree-based; Edit-distance; Classification;
D O I
10.1007/s10207-017-0393-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Whenever web-application executes dynamic SQL statements it may come under SQL injection attack. To evaluate the existing practices of its detection, we consider two different security scenarios for the web-application authentication that generates dynamic SQL query with the user input data. Accordingly, we generate two different datasets by considering all possible vulnerabilities in the run-time queries. We present proposed approach based on edit-distance to classify a dynamic SQL query as normal or malicious using web-profile prepared with the dynamic SQL queries during training phase. We evaluate the dataset using proposed approach and some well-known supervised classification approaches. Our proposed method is found more effective in detecting SQL injection attack under both the scenarios of authentication security.
引用
收藏
页码:1 / 22
页数:22
相关论文
共 16 条
  • [1] CANDID: Dynamic Candidate Evaluations for Automatic Prevention of SQL Injection Attacks
    Bisht, Prithvi
    Madhusudan, P.
    Venkatakrishnan, V. N.
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (02)
  • [2] CISCO, 2010, CISCO WORLDW REP SPA
  • [3] SUPPORT-VECTOR NETWORKS
    CORTES, C
    VAPNIK, V
    [J]. MACHINE LEARNING, 1995, 20 (03) : 273 - 297
  • [4] Halfond W. G., 2006, P 14 ACM SIGSOFT INT, P175, DOI DOI 10.1145/1181775.1181797
  • [5] John G. H., 1995, UAI 95 P 11 C UNC AR
  • [6] Pixy: A static analysis tool for detecting Web application vulnerabilities - (Short paper)
    Jovanovic, Nenad
    Kruegel, Christopher
    Kirda, Engin
    [J]. 2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2006, : 258 - +
  • [7] A multi-channel architecture for high-performance NAND flash-based storage system
    Kang, Jeong-Uk
    Kim, Jin-Soo
    Park, Chanik
    Park, Hyoungjun
    Lee, Joonwon
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2007, 53 (09) : 644 - 658
  • [8] Le H. T., LATEST ADV INFORM SC
  • [9] Levenshtein V. I., SOVIET PHYS DOKLADY, V10
  • [10] Liu A., 2009, P 2009 ACM S APPL CO, P2054