• DocumentCode
    2621768
  • Title

    Access Control Mechanism For Web Databases By Using Parameterized Cursor

  • Author

    Jan, Zahoor ; Shah, Muhammad ; Rauf, Azhar ; Khan, Mohd Amir ; Mahfooz, Saeed

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Peshawar, Peshawar, Pakistan
  • fYear
    2010
  • fDate
    21-23 May 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Web applications have gained an enormous increase in popularity for providing various facilities online, such as e-shopping, e-banking, e-ticketing, e-learning etc. As the use of web applications grow, there is an increase in the attacks on web applications as well. Among these attacking techniques, SQL Injection has been emerging as one of the most dangerous threats to web applications. SQL Injection technique is mostly an attack on data driven web applications. By providing especially built user input through the web form fields, the attacker can access and modify the contents of the underlying database of a web application. This research work presents a technique, which will be used for the detection and prevention from SQL Injection. The parameterized cursor is used to implement the concept. The user session information will be passed as a parameter to cursor. If the user is an authorized user then the cursor will fetch the desired tuples else will fail to execute. This research work can easily be adopted and implemented in any platform and database. An example application is developed in Oracle Internet Developer suite 10g and Oracle Database 10g to test the performance against SQL Injection.
  • Keywords
    Internet; SQL; authorisation; Oracle Database 10g; Oracle Internet developer; SQL injection technique; Web databases; access control mechanism; data driven Web applications; parameterized cursor; Access control; Application software; Companies; Computer science; Databases; Decision making; Electronic learning; Information analysis; Information security; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Future Information Technology (FutureTech), 2010 5th International Conference on
  • Conference_Location
    Busan
  • Print_ISBN
    978-1-4244-6948-2
  • Type

    conf

  • DOI
    10.1109/FUTURETECH.2010.5482721
  • Filename
    5482721