DocumentCode :
568514
Title :
Random4: An Application Specific Randomized Encryption Algorithm to Prevent SQL Injection
Author :
Avireddy, Srinivas ; Perumal, Varalakshmi ; Gowraj, Narayan ; Kannan, Ram Srivatsa ; Thinakaran, Prashanth ; Ganapthi, S. ; Gunasekaran, Jashwant Raj ; Prabhu, Sruthi
Author_Institution :
Dept. of Inf. Technol., Anna Univ., Chennai, China
fYear :
2012
fDate :
25-27 June 2012
Firstpage :
1327
Lastpage :
1333
Abstract :
Web Applications form an integral part of our day to day life. The number of attacks on websites and the compromise of many individuals´ secure data are increasing at an alarming rate. With the advent of social networking and e-commerce, Web security attacks such as phishing and spamming have become quite common. The consequences of these attacks are ruthless. Hence, providing increased amount of security for the users and their data becomes essential. Most important vulnerability as described in top 10 web security issues by Open Web Application Security Project is SQL Injection Attack (SQLIA) [3]. This paper focuses on how the advantages of randomization can be employed to prevent SQL injection attacks in web based applications. SQL injection can be used for unauthorized access to a database to penetrate the application illegally, modify the database or even remove it. For a hacker to modify a database, details such as field and table names are required. So we try to propose a solution to the above problem by preventing it using an encryption algorithm based on randomization. It has better performance and provides increased security in comparison to the existing solutions. Also the time to crack the database takes more time when techniques such as dictionary and brute force attack are deployed. Our main aim is to provide increased security by developing a tool which prevents illegal access to the database.
Keywords :
Internet; SQL; cryptography; Random4; SQL injection attacks; Web applications; Web security; Web security attacks; e-commerce; open Web application security project; phishing; randomized encryption algorithm; social networking; spamming; Algorithm design and analysis; Computer hacking; Databases; Encryption; Servers; SQL injection; Vulnerability; randomization; web security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4673-2172-3
Type :
conf
DOI :
10.1109/TrustCom.2012.232
Filename :
6296134
Link To Document :
بازگشت