DocumentCode :
584812
Title :
Object oriented approach to SQL injection preventer
Author :
Giri, D.R. ; Kumar, Sathiya Prabhu ; Prasannakumar, L. ; Murthy, R.N.V.V.
Author_Institution :
Dept. of IT, SRKR Eng. Coll., Bhimavaram, India
fYear :
2012
fDate :
26-28 July 2012
Firstpage :
1
Lastpage :
7
Abstract :
Many web applications can be exposed to a variety of Web-based attacks. One of these attacks is SQL injection, which can give attackers unrestricted access to the databases and has become increasingly frequent and serious. This paper presents a new highly automated approach for protecting Web applications against SQL injection that has both theoretical and practical advantages over most existing techniques. From a theoretical view, the approach is based on the idea of positive tainting and on the concept of syntax-aware evaluation. From a practical view, our technique is efficient, has minimal deployment requirements, and has a negligible performance overhead in most cases. We have implemented our techniques in the Web Application SQL-injection Preventer (WASP) tool, where a wide range of Web applications were subjected to a large and varied set of attacks and legal accesses. We considered login validation of user in an online banking system. WASP was able to stop all of these attacks and did not generate any false positives.
Keywords :
Internet; SQL; object-oriented programming; security of data; WASP; Web application SQL injection preventer; Web based attacks; database access; object oriented approach; syntax aware evaluation; Computer architecture; Servers; Software; Injection; SQL; WASP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computing Communication & Networking Technologies (ICCCNT), 2012 Third International Conference on
Conference_Location :
Coimbatore
Type :
conf
DOI :
10.1109/ICCCNT.2012.6395979
Filename :
6395979
Link To Document :
بازگشت