• DocumentCode
    2776476
  • Title

    An Automatic Revised Tool for Anti-Malicious Injection

  • Author

    Lin, Jin-Cherng ; Chen, Jan-Min

  • Author_Institution
    Tatung University, Taiwan
  • fYear
    2006
  • fDate
    Sept. 2006
  • Firstpage
    164
  • Lastpage
    164
  • Abstract
    Many web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Some sites attempt to protect themselves by filtering malicious input, but a surprising number of web applications have used no mechanisms to validate input. We have developed a advanced tool that can producing a proper input validation function depending on the database server and the application framework. The tool can automatically insert input proper validation function into the server-side program to eliminate vulnerabilities based on malicious injection. To verify the Efficiency of the tool, we picked the websites made up of some example programs included in the books or created by some web generator tools. Among our experiments, the websites have been automatically injected validation function to avoid malicious injection attack.
  • Keywords
    Application software; Application specific processors; Books; Data security; Databases; Information filtering; Information filters; Inspection; Protection; Runtime; Complete crawling; Input; Malicious injection; SQL Injection; Security.; validation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology, 2006. CIT '06. The Sixth IEEE International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    0-7695-2687-X
  • Type

    conf

  • DOI
    10.1109/CIT.2006.40
  • Filename
    4019951