Title :
A network based vulnerability scanner for detecting SQLI attacks in web applications
Author :
Singh, Avinash Kumar ; Roy, Sangita
Author_Institution :
Robot. & Artificial Intell. Lab., Indian Inst. of Inf. Technol., Allahabad, India
Abstract :
Today is the world of information era, where information is available on just our single click. Web applications are playing a magnificent role in this, every organizations are mapping their business from a room to the world with the help of these Web Apps. Web applications generally consist of a three tier architecture where database is in the third pole, which is the most valuable assets in any organization, as the adaptation of web applications are increases day by day, various attacks are possible against this. SQL injection is an attack in which an attacker directly compromises the database, that´s why this is a most threatening attack. Various Vulnerability scanners has been proposed to deal with this, but none of them are able to detect SQLI completely, the existing tools have the accuracy ratio very less as well as they produce a high rate of false positive, apart from that all these tools take much time to scan. So here we are presenting a network based vulnerability scanner approach which provides a better coverage and with no false positive within a short span of time.
Keywords :
Internet; SQL; security of data; SQL injection attack; SQLI attack detection; Web Apps; Web applications; database; network based vulnerability scanner; three tier architecture; Databases; Information technology; Libraries; Payloads; Security; Servers; Testing; SQL injection attacks; Vulnerability Scanner; Web application;
Conference_Titel :
Recent Advances in Information Technology (RAIT), 2012 1st International Conference on
Conference_Location :
Dhanbad
Print_ISBN :
978-1-4577-0694-3
DOI :
10.1109/RAIT.2012.6194594