DocumentCode :
1843321
Title :
An Automatic Mechanism for Sanitizing Malicious Injection
Author :
Lin, Jin-Cherng ; Chen, Jan-Min ; Liu, Cheng-Hsiung
Author_Institution :
Dept. of Comput. Sci & Eng, Tatung Univ., Taipei
fYear :
2008
fDate :
18-21 Nov. 2008
Firstpage :
1470
Lastpage :
1475
Abstract :
According to OWASP Top 10 2007, top 1-5 critical Web application security vulnerabilities caused by unchecked input [1]. Unvalidated Input may lead hacker to inject code to bypass or modify the originally intended functionality of the program to gain information, privilege escalation or unauthorized access to a system. Examples of such vulnerabilities are SQL injection, Shell injection and Cross Site Scripting (XSS). Proper input validation is an effective countermeasure to act as a defense against input attacks but it may induce false negative or false positive. We develop a defense system consisting of a testing framework and a sanitizing mechanism on a security gateway. The security gateway is allocated in front of application server to mitigate malicious injection. To verify the efficiency of the sanitizing mechanism, we focus on whether the filter rules have better detection rate to sanitize input data. Among our experiments, different fields may be automatically injected proper validation rules made up of some sub-rules. By means of the mechanism, we reduce false rate and prove that the hybrid method is more ideal than any traditional input handling.
Keywords :
invasive software; program testing; program verification; SQL injection; automatic mechanism; cross site scripting; sanitizing malicious injection; security gateway; shell injection; testing framework; Conference management; Data security; Databases; Educational institutions; Filtering; Filters; Information management; Proposals; System testing; Technology management; Bypass testing; Input validation; Malicious injection; Security gateway;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
Conference_Location :
Hunan
Print_ISBN :
978-0-7695-3398-8
Electronic_ISBN :
978-0-7695-3398-8
Type :
conf
DOI :
10.1109/ICYCS.2008.182
Filename :
4709190
Link To Document :
بازگشت