Title :
New mechanism to confront injection attacks
Author :
Dolatabadi, Hossein ; Shirazi, Mahdi Negahi ; Hejazi, Maryamsadat
Author_Institution :
Fac. of Inf. Technol., Multimedia Univ., Kualalumpur, Malaysia
Abstract :
Computer as a functional and effective tool for changing and improving human life, concerns with variety of knowledge areas and techniques. These knowledge areas comprise both technical and managerial tools and skills. Moreover, developing a computer application using human resource and other technical resources drastically require fund and expense. In this case, making an appropriate and reliable infrastructure for developing software products is critical to assure IT projects success. This article concentrates on variant aspects of XML security environment and its related security attacks namely DoS and XML injection. Both of them are of the most abused techniques by hackers to disrupt web services data hoarding, to influence on web servers and to penetrate into the servers as a legal user. Then, it will offer a new method to prevent XML injection attacks by adding a new component to the software systems for changing the data section of the XML data code characters in such a way that it will become more secure in face of XML injection attacks.
Keywords :
Web services; XML; information technology; security of data; DoS; IT projects; Web servers; Web services; XML data code; XML injection; XML security environment; computer application; human resource; injection attacks; knowledge areas; knowledge techniques; security attacks; software products; HTML; Security; XML; DTD: Document Type Definition; DoS: Denial of service; HTTP: Hyper Text Transfer Protocol; SMTP: Simple Mail Transfer Protocol; SOAP: Simple Object Access Protocol; XHTML: extensible Hypertext Markup Language; XML Schema; XML injection; XML: Extensible Markup Language;
Conference_Titel :
Communication Software and Networks (ICCSN), 2011 IEEE 3rd International Conference on
Conference_Location :
Xi´an
Print_ISBN :
978-1-61284-485-5
DOI :
10.1109/ICCSN.2011.6014015