• DocumentCode
    596117
  • Title

    Semi-Automated Verification of Defense against SQL Injection in Web Applications

  • Author

    Kaiping Liu ; Hee Beng Kuan Tan ; Shar, L.K.

  • Author_Institution
    Sch. of Electr. & Electron. Eng., Nanyang Technol. Univ., Singapore, Singapore
  • Volume
    1
  • fYear
    2012
  • fDate
    4-7 Dec. 2012
  • Firstpage
    91
  • Lastpage
    96
  • Abstract
    Recent reports reveal that majority of the attacks to Web applications are input manipulation attacks. Among these attacks, SQL injection attack malicious input is submitted to manipulate the database in a way that was unintended by the applications´ developers is one such attack. This paper proposes an approach for assisting to code verification process on the defense against SQL injection. The approach extracts all such defenses implemented in code. With the use of the proposed approach, developers, testers or auditors can then check the defenses extracted from code to verify their adequacy. We have evaluated the feasibility, effectiveness, and usefulness of the proposed approach by a set of open-source systems. Our experiment results showed that the proposed approach is effective in extracting all the possible defenses implemented/adopted by Web applications. We observed that the proposed approach would be useful in identifying the false positive cases resulting from other related approaches and auditing the code in order to fix the actual vulnerable cases.
  • Keywords
    Internet; formal verification; security of data; SQL injection; Structured Query Language; Web application; code verification process; database; manipulation attack; open source system; semiautomated defense verification; Computer hacking; Educational institutions; Filtering; Filtering algorithms; Input variables; Vectors; SQL injection; Web applications; code auditing; software security; static analysis; vulnerabilities;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Conference (APSEC), 2012 19th Asia-Pacific
  • Conference_Location
    Hong Kong
  • ISSN
    1530-1362
  • Print_ISBN
    978-1-4673-4930-7
  • Type

    conf

  • DOI
    10.1109/APSEC.2012.18
  • Filename
    6462643