Visible to the public Detection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack

TitleDetection model for SQL injection attack: An approach for preventing a web application from the SQL injection attack
Publication TypeConference Paper
Year of Publication2014
AuthorsBuja, G., Bin Abd Jalil, K., Bt Hj Mohd Ali, F., Rahman, T.F.A.
Conference NameComputer Applications and Industrial Electronics (ISCAIE), 2014 IEEE Symposium on
Date PublishedApril
Keywordsauthorisation, Computational modeling, Computer crime, cross-site request forgery, cross-site scripting, CSRF, Databases, hacking tools, hacking tutorials, Internet, security, SQL, SQL Injection, SQL injection attack, structured query language injection, system cracker, Testing, Uniform resource locators, vulneralbilities, Web application, Web application vulnerabilities, web applicationt, Web pages, Web vulnerability detection model, XSS
Abstract

Since the past 20 years the uses of web in daily life is increasing and becoming trend now. As the use of the web is increasing, the use of web application is also increasing. Apparently most of the web application exists up to today have some vulnerability that could be exploited by unauthorized person. Some of well-known web application vulnerabilities are Structured Query Language (SQL) Injection, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). By compromising with these web application vulnerabilities, the system cracker can gain information about the user and lead to the reputation of the respective organization. Usually the developers of web applications did not realize that their web applications have vulnerabilities. They only realize them when there is an attack or manipulation of their code by someone. This is normal as in a web application, there are thousands of lines of code, therefore it is not easy to detect if there are some loopholes. Nowadays as the hacking tools and hacking tutorials are easier to get, lots of new hackers are born. Even though SQL injection is very easy to protect against, there are still large numbers of the system on the internet are vulnerable to this type of attack because there will be a few subtle condition that can go undetected. Therefore, in this paper we propose a detection model for detecting and recognizing the web vulnerability which is; SQL Injection based on the defined and identified criteria. In addition, the proposed detection model will be able to generate a report regarding the vulnerability level of the web application. As the consequence, the proposed detection model should be able to decrease the possibility of the SQL Injection attack that can be launch onto the web application.

URLhttps://ieeexplore.ieee.org/document/7010210
DOI10.1109/ISCAIE.2014.7010210
Citation Key7010210