Title :
SQL injections attack and session hijacking on e-learning systems
Author :
Sum Keng Chung ; Ow Chee Yee ; Singh, Manmeet Mahinderjit ; Hassan, Rohail
Author_Institution :
Sch. of Comput. Sci., Univ. Sains Malaysia, Minden, Malaysia
Abstract :
E-learning enables acquisition of knowledge and information through technologies such as computers, smartphones, tablets and wide area networks. The existence of e-learning does contribute in the field of education field such as in the university because its improve the education quality and distributing and sharing of teaching material efficiently. However, due to the open-network in which e-learning tools resides, it is prone to various security attacks. In this paper, we will classify e-learning technology security based attacks into classification via active and passive attacks. Next, two major attacks which is the SQL injection attack and session hijacking is explored in-depth. Case study for each attack to investigate the vulnerabilities in e-learning system and mechanism of solutions to tackle this attack is also presented. An evaluation of the proposed solutions against the X.800 security architecture is done at the end of the study.
Keywords :
SQL; computer aided instruction; pattern classification; security of data; teaching; SQL injection attack; X.800 security architecture; active attacks; e-learning systems; e-learning technology security classification; e-learning tools; education field; education quality; information acquisition; knowledge acquisition; open-network; passive attacks; security attacks; session hijacking; teaching material sharing; Authentication; Electronic learning; Encryption; Servers; Software; E-learning; SQL injection; Security; Session Hijacking; X.800 security architecture;
Conference_Titel :
Computer, Communications, and Control Technology (I4CT), 2014 International Conference on
Conference_Location :
Langkawi
Print_ISBN :
978-1-4799-4556-6
DOI :
10.1109/I4CT.2014.6914201