DocumentCode
568514
Title
Random4: An Application Specific Randomized Encryption Algorithm to Prevent SQL Injection
Author
Avireddy, Srinivas ; Perumal, Varalakshmi ; Gowraj, Narayan ; Kannan, Ram Srivatsa ; Thinakaran, Prashanth ; Ganapthi, S. ; Gunasekaran, Jashwant Raj ; Prabhu, Sruthi
Author_Institution
Dept. of Inf. Technol., Anna Univ., Chennai, China
fYear
2012
fDate
25-27 June 2012
Firstpage
1327
Lastpage
1333
Abstract
Web Applications form an integral part of our day to day life. The number of attacks on websites and the compromise of many individuals´ secure data are increasing at an alarming rate. With the advent of social networking and e-commerce, Web security attacks such as phishing and spamming have become quite common. The consequences of these attacks are ruthless. Hence, providing increased amount of security for the users and their data becomes essential. Most important vulnerability as described in top 10 web security issues by Open Web Application Security Project is SQL Injection Attack (SQLIA) [3]. This paper focuses on how the advantages of randomization can be employed to prevent SQL injection attacks in web based applications. SQL injection can be used for unauthorized access to a database to penetrate the application illegally, modify the database or even remove it. For a hacker to modify a database, details such as field and table names are required. So we try to propose a solution to the above problem by preventing it using an encryption algorithm based on randomization. It has better performance and provides increased security in comparison to the existing solutions. Also the time to crack the database takes more time when techniques such as dictionary and brute force attack are deployed. Our main aim is to provide increased security by developing a tool which prevents illegal access to the database.
Keywords
Internet; SQL; cryptography; Random4; SQL injection attacks; Web applications; Web security; Web security attacks; e-commerce; open Web application security project; phishing; randomized encryption algorithm; social networking; spamming; Algorithm design and analysis; Computer hacking; Databases; Encryption; Servers; SQL injection; Vulnerability; randomization; web security;
fLanguage
English
Publisher
ieee
Conference_Titel
Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
Conference_Location
Liverpool
Print_ISBN
978-1-4673-2172-3
Type
conf
DOI
10.1109/TrustCom.2012.232
Filename
6296134
Link To Document