Title of article
A Framework for Evaluation of SQL Injection Detection and Prevention Tools
Author/Authors
Tajpour ، Atefeh نويسنده Advanced Informatics School , , Ibrahim، Suhaimi نويسنده Advanced Informatics School ,
Issue Information
فصلنامه با شماره پیاپی 19 سال 2013
Pages
8
From page
55
To page
62
Abstract
SQLIA is a hacking technique by which the attacker adds Structured Query Language code (SQL
statements) through a web applicationʹs input fields or hidden parameters to access the resources. By SQL injection
an attacker gains access to underlying web applicationʹs database and destroys functionality and/or confidentiality.
Researchers have proposed different techniques to detect and prevent this vulnerability. In this paper we present SQL
injection attack types and also current security tools which detect or prevent this attack and compare them with each
other. Finally, we propose a framework for evaluating SQL injection detection or prevention tools in common
criteria. In fact, this paper provides information about current tools for researchers and also helps security officers to
choose suitable SQL injection detection tools for their web application security.
Journal title
International Journal of Information and Communication Technology Research
Serial Year
2013
Journal title
International Journal of Information and Communication Technology Research
Record number
944490
Link To Document