DocumentCode
2621768
Title
Access Control Mechanism For Web Databases By Using Parameterized Cursor
Author
Jan, Zahoor ; Shah, Muhammad ; Rauf, Azhar ; Khan, Mohd Amir ; Mahfooz, Saeed
Author_Institution
Dept. of Comput. Sci., Univ. of Peshawar, Peshawar, Pakistan
fYear
2010
fDate
21-23 May 2010
Firstpage
1
Lastpage
6
Abstract
Web applications have gained an enormous increase in popularity for providing various facilities online, such as e-shopping, e-banking, e-ticketing, e-learning etc. As the use of web applications grow, there is an increase in the attacks on web applications as well. Among these attacking techniques, SQL Injection has been emerging as one of the most dangerous threats to web applications. SQL Injection technique is mostly an attack on data driven web applications. By providing especially built user input through the web form fields, the attacker can access and modify the contents of the underlying database of a web application. This research work presents a technique, which will be used for the detection and prevention from SQL Injection. The parameterized cursor is used to implement the concept. The user session information will be passed as a parameter to cursor. If the user is an authorized user then the cursor will fetch the desired tuples else will fail to execute. This research work can easily be adopted and implemented in any platform and database. An example application is developed in Oracle Internet Developer suite 10g and Oracle Database 10g to test the performance against SQL Injection.
Keywords
Internet; SQL; authorisation; Oracle Database 10g; Oracle Internet developer; SQL injection technique; Web databases; access control mechanism; data driven Web applications; parameterized cursor; Access control; Application software; Companies; Computer science; Databases; Decision making; Electronic learning; Information analysis; Information security; Protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Future Information Technology (FutureTech), 2010 5th International Conference on
Conference_Location
Busan
Print_ISBN
978-1-4244-6948-2
Type
conf
DOI
10.1109/FUTURETECH.2010.5482721
Filename
5482721
Link To Document