Skip to main navigation Skip to search Skip to main content

SQLStor: blockage of stored procedure SQL injection attack using dynamic query structure validation

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Web applications are becoming an important part of our daily life. So attacks against them also increases rapidly. Of these attacks, a major role is held by SQL injection attacks (SQLIA). This paper proposes a new method for preventing SQL injection attacks in JSP web applications. The basic idea is to check before execution, the intended structure of the SQL query. For this we use semantic comparison. This method prevents different kinds of injection attacks including stored procedure attack which is more difficult and less considered in the literature.
Original languageEnglish
Title of host publication2012 12th International Conference on Intelligent Systems Design and Applications (ISDA)
Place of PublicationPiscataway, New Jersey
PublisherIEEE
Pages240-245
Number of pages6
ISBN (Electronic)9781467351195, 9781467351188
ISBN (Print)9781467351171
DOIs
Publication statusPublished - 24 Dec 2013
Externally publishedYes

Publication series

NameIEEE Conference Proceedings
PublisherIEEE
ISSN (Print)2164-7143
ISSN (Electronic)2164-7151

Keywords

  • arraylist
  • parse tree
  • semantics
  • SQL injection
  • web application

Fingerprint

Dive into the research topics of 'SQLStor: blockage of stored procedure SQL injection attack using dynamic query structure validation'. Together they form a unique fingerprint.

Cite this