Moving Target Defense Against Injection Attacks

被引:1
|
作者
Zhang, Huan [1 ]
Zheng, Kangfeng [1 ]
Yan, Xiaodan [1 ]
Luo, Shoushan [1 ]
Wu, Bin [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
关键词
Moving target defense; SQL injection attack; WEB service; Mutation period; Network security; TOOL;
D O I
10.1007/978-3-030-38991-8_34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of network technology, web services become more convenient and popular. However, web services are also facing serious security threats, especially SQL injection attack(SQLIA). Due to the diversity of attack techniques and the static of defense configurations, it is difficult for existing passive defence methods to effectively defend against all SQLIAs. To reduce the risk of successful SQLIAs and increase the difficulty of the attacker, an effective defence technique based on moving target defence (MTD) called dynamic defence to SQLIA (DTSA) was presented in this article. DTSA diversifies the types of databases and implementation languages dynamically, turns the Web server into an untraceable and unpredictable moving target and slows down SQLIAs. Moreover, the period of mutation was determined by the concept of dynamic programming so as to reduce the hazards caused by SQLIAs and minimize the impact on normal users as much as possible. Final, the experimental results showed that the proposed defence method can effectively defend against injection attacks in relational databases.
引用
收藏
页码:518 / 532
页数:15
相关论文
共 50 条
  • [41] Moving Target Defense Approach to Detecting Stuxnet-Like Attacks
    Tian, Jue
    Tan, Rui
    Guan, Xiaohong
    Xu, Zhanbo
    Liu, Ting
    IEEE TRANSACTIONS ON SMART GRID, 2020, 11 (01) : 291 - 300
  • [42] A Lightweight Compound Defense Framework Against Injection Attacks in IIoT
    Chi, Po-Wen
    Wang, Ming-Hung
    2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 30 - 37
  • [43] Moving-Target Defense Against Cyber-Physical Attacks in Power Grids via Game Theory
    Lakshminarayana, Subhash
    Belmega, E. Veronica
    Poor, H. Vincent
    IEEE TRANSACTIONS ON SMART GRID, 2021, 12 (06) : 5244 - 5257
  • [44] Optimal Deployment in Moving Target Defense against Coordinated Cyber-Physical Attacks via Game Theory
    Yu, Jian
    Li, Qiang
    ELECTRONICS, 2023, 12 (11)
  • [45] Random-based Hidden Moving Target Defense against Alert False Data Injection Attackers
    Liu, Bo
    Yang, Qihui
    Zhang, Hang
    Liu, Xuebo
    Wu, Hongyu
    2023 IEEE POWER & ENERGY SOCIETY GENERAL MEETING, PESGM, 2023,
  • [46] Parameter-Estimate-First False Data Injection Attacks in AC State Estimation Deployed With Moving Target Defense
    Liu, Chensheng
    Li, Yuanqi
    Zhu, Hongcheng
    Tang, Yang
    Du, Wenli
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2024, 71 (04) : 1842 - 1851
  • [47] Random-Enabled Hidden Moving Target Defense against False Data Injection Alert Attackers
    Liu, Bo
    Wu, Hongyu
    Yang, Qihui
    Zhang, Hang
    PROCESSES, 2023, 11 (02)
  • [48] A Moving Target Defense to Detect Stealthy Attacks in Cyber-Physical Systems
    Giraldo, J.
    Cardenas, A.
    Sanfelice, R. G.
    2019 AMERICAN CONTROL CONFERENCE (ACC), 2019, : 391 - 396
  • [49] Circuit-Variant Moving Target Defense for Side-Channel Attacks
    Mullins, Tristen
    Baggett, Brandon
    Andel, Todd R.
    McDonald, J. Todd
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 219 - 226
  • [50] Deep-Reinforcement-Learning-Based Self-Evolving Moving Target Defense Approach Against Unknown Attacks
    Cao, Yuan
    Liu, Kun
    Lin, Yeming
    Wang, Luyao
    Xia, Yuanqing
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (20): : 33027 - 33039