DocumentCode :
1987215
Title :
Attack Model Based Penetration Test for SQL Injection Vulnerability
Author :
Tian Wei ; Yang Ju-Feng ; Xu Jing ; Si Guan-Nan
Author_Institution :
Coll. of Inf. Tech. Sci., Nankai Univ., Tianjin, China
fYear :
2012
fDate :
16-20 July 2012
Firstpage :
589
Lastpage :
594
Abstract :
The penetration test is a crucial way to enhance the security of web applications. Improving accuracy is the core issue of the penetration test research. The test case is an important factor affecting the penetration test accuracy. In this paper, we discuss how to generate more effective penetration test case inputs to detect the SQL injection vulnerability hidden behind the inadequate blacklist filter defense mechanism in web applications. We propose a model based penetration test method for the SQL injection vulnerability, in which the penetration test case generation is divided into two steps: i) Building model for the penetration test case, and ii) Instantiating the model of penetration test case. Our method can generate test case covering more types and patterns of SQL injection attack input to thoroughly test the blacklist filter mechanism of web applications. Experiments show the penetration test case generated by our method can effectively find the SQL injection vulnerabilities hidden behind the inadequate blacklist filter defense mechanism thus reduce the false negative and improve test accuracy.
Keywords :
Internet; SQL; program testing; security of data; SQL injection vulnerability; Web applications; attack model based penetration test; blacklist filter defense mechanism; penetration test case inputs; security enhancement; Accuracy; Analytical models; Databases; Indium phosphide; Security; Software; Vectors; SQL injection; attack model; penetration test; test case; vulnerability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference Workshops (COMPSACW), 2012 IEEE 36th Annual
Conference_Location :
Izmir
Print_ISBN :
978-1-4673-2714-5
Electronic_ISBN :
978-0-7695-4758-9
Type :
conf
DOI :
10.1109/COMPSACW.2012.108
Filename :
6341640
Link To Document :
بازگشت