• DocumentCode
    568514
  • Title

    Random4: An Application Specific Randomized Encryption Algorithm to Prevent SQL Injection

  • Author

    Avireddy, Srinivas ; Perumal, Varalakshmi ; Gowraj, Narayan ; Kannan, Ram Srivatsa ; Thinakaran, Prashanth ; Ganapthi, S. ; Gunasekaran, Jashwant Raj ; Prabhu, Sruthi

  • Author_Institution
    Dept. of Inf. Technol., Anna Univ., Chennai, China
  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    1327
  • Lastpage
    1333
  • Abstract
    Web Applications form an integral part of our day to day life. The number of attacks on websites and the compromise of many individuals´ secure data are increasing at an alarming rate. With the advent of social networking and e-commerce, Web security attacks such as phishing and spamming have become quite common. The consequences of these attacks are ruthless. Hence, providing increased amount of security for the users and their data becomes essential. Most important vulnerability as described in top 10 web security issues by Open Web Application Security Project is SQL Injection Attack (SQLIA) [3]. This paper focuses on how the advantages of randomization can be employed to prevent SQL injection attacks in web based applications. SQL injection can be used for unauthorized access to a database to penetrate the application illegally, modify the database or even remove it. For a hacker to modify a database, details such as field and table names are required. So we try to propose a solution to the above problem by preventing it using an encryption algorithm based on randomization. It has better performance and provides increased security in comparison to the existing solutions. Also the time to crack the database takes more time when techniques such as dictionary and brute force attack are deployed. Our main aim is to provide increased security by developing a tool which prevents illegal access to the database.
  • Keywords
    Internet; SQL; cryptography; Random4; SQL injection attacks; Web applications; Web security; Web security attacks; e-commerce; open Web application security project; phishing; randomized encryption algorithm; social networking; spamming; Algorithm design and analysis; Computer hacking; Databases; Encryption; Servers; SQL injection; Vulnerability; randomization; web security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.232
  • Filename
    6296134