DocumentCode
1987215
Title
Attack Model Based Penetration Test for SQL Injection Vulnerability
Author
Tian Wei ; Yang Ju-Feng ; Xu Jing ; Si Guan-Nan
Author_Institution
Coll. of Inf. Tech. Sci., Nankai Univ., Tianjin, China
fYear
2012
fDate
16-20 July 2012
Firstpage
589
Lastpage
594
Abstract
The penetration test is a crucial way to enhance the security of web applications. Improving accuracy is the core issue of the penetration test research. The test case is an important factor affecting the penetration test accuracy. In this paper, we discuss how to generate more effective penetration test case inputs to detect the SQL injection vulnerability hidden behind the inadequate blacklist filter defense mechanism in web applications. We propose a model based penetration test method for the SQL injection vulnerability, in which the penetration test case generation is divided into two steps: i) Building model for the penetration test case, and ii) Instantiating the model of penetration test case. Our method can generate test case covering more types and patterns of SQL injection attack input to thoroughly test the blacklist filter mechanism of web applications. Experiments show the penetration test case generated by our method can effectively find the SQL injection vulnerabilities hidden behind the inadequate blacklist filter defense mechanism thus reduce the false negative and improve test accuracy.
Keywords
Internet; SQL; program testing; security of data; SQL injection vulnerability; Web applications; attack model based penetration test; blacklist filter defense mechanism; penetration test case inputs; security enhancement; Accuracy; Analytical models; Databases; Indium phosphide; Security; Software; Vectors; SQL injection; attack model; penetration test; test case; vulnerability;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference Workshops (COMPSACW), 2012 IEEE 36th Annual
Conference_Location
Izmir
Print_ISBN
978-1-4673-2714-5
Electronic_ISBN
978-0-7695-4758-9
Type
conf
DOI
10.1109/COMPSACW.2012.108
Filename
6341640
Link To Document