DocumentCode
2776476
Title
An Automatic Revised Tool for Anti-Malicious Injection
Author
Lin, Jin-Cherng ; Chen, Jan-Min
Author_Institution
Tatung University, Taiwan
fYear
2006
fDate
Sept. 2006
Firstpage
164
Lastpage
164
Abstract
Many web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Some sites attempt to protect themselves by filtering malicious input, but a surprising number of web applications have used no mechanisms to validate input. We have developed a advanced tool that can producing a proper input validation function depending on the database server and the application framework. The tool can automatically insert input proper validation function into the server-side program to eliminate vulnerabilities based on malicious injection. To verify the Efficiency of the tool, we picked the websites made up of some example programs included in the books or created by some web generator tools. Among our experiments, the websites have been automatically injected validation function to avoid malicious injection attack.
Keywords
Application software; Application specific processors; Books; Data security; Databases; Information filtering; Information filters; Inspection; Protection; Runtime; Complete crawling; Input; Malicious injection; SQL Injection; Security.; validation;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology, 2006. CIT '06. The Sixth IEEE International Conference on
Conference_Location
Seoul
Print_ISBN
0-7695-2687-X
Type
conf
DOI
10.1109/CIT.2006.40
Filename
4019951
Link To Document