Detection of SQL injection and XSS attacks in three tier web applications
Title | Detection of SQL injection and XSS attacks in three tier web applications |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Sonewar, P. A., Thosar, S. D. |
Conference Name | 2016 International Conference on Computing Communication Control and automation (ICCUBEA) |
Keywords | composability, Cross Site Scripting, Cross Site Scripting (XSS), Databases, Dynamic Web Application (DWA), Human Behavior, Intrusion Detection System (IDS), pubcrawl, Resiliency, security, Skeleton, SQL injection attack, Static Web Application (SWA), Three Tier Web Application, virtualization, Web Security Vulnerability, Web servers |
Abstract | Web applications are used on a large scale worldwide, which handles sensitive personal data of users. With web application that maintains data ranging from as simple as telephone number to as important as bank account information, security is a prime point of concern. With hackers aimed to breakthrough this security using various attacks, we are focusing on SQL injection attacks and XSS attacks. SQL injection attack is very common attack that manipulates the data passing through web application to the database servers through web servers in such a way that it alters or reveals database contents. While Cross Site Scripting (XSS) attacks focuses more on view of the web application and tries to trick users that leads to security breach. We are considering three tier web applications with static and dynamic behavior, for security. Static and dynamic mapping model is created to detect anomalies in the class of SQL Injection and XSS attacks. |
URL | https://ieeexplore.ieee.org/document/7860069 |
DOI | 10.1109/ICCUBEA.2016.7860069 |
Citation Key | sonewar_detection_2016 |
- Resiliency
- Web servers
- Web Security Vulnerability
- Virtualization
- Three Tier Web Application
- Static Web Application (SWA)
- SQL injection attack
- Skeleton
- security
- composability
- pubcrawl
- Intrusion Detection System (IDS)
- Human behavior
- Dynamic Web Application (DWA)
- Databases
- Cross Site Scripting (XSS)
- Cross Site Scripting