• DocumentCode
    3226506
  • Title

    New mechanism to confront injection attacks

  • Author

    Dolatabadi, Hossein ; Shirazi, Mahdi Negahi ; Hejazi, Maryamsadat

  • Author_Institution
    Fac. of Inf. Technol., Multimedia Univ., Kualalumpur, Malaysia
  • fYear
    2011
  • fDate
    27-29 May 2011
  • Firstpage
    112
  • Lastpage
    115
  • Abstract
    Computer as a functional and effective tool for changing and improving human life, concerns with variety of knowledge areas and techniques. These knowledge areas comprise both technical and managerial tools and skills. Moreover, developing a computer application using human resource and other technical resources drastically require fund and expense. In this case, making an appropriate and reliable infrastructure for developing software products is critical to assure IT projects success. This article concentrates on variant aspects of XML security environment and its related security attacks namely DoS and XML injection. Both of them are of the most abused techniques by hackers to disrupt web services data hoarding, to influence on web servers and to penetrate into the servers as a legal user. Then, it will offer a new method to prevent XML injection attacks by adding a new component to the software systems for changing the data section of the XML data code characters in such a way that it will become more secure in face of XML injection attacks.
  • Keywords
    Web services; XML; information technology; security of data; DoS; IT projects; Web servers; Web services; XML data code; XML injection; XML security environment; computer application; human resource; injection attacks; knowledge areas; knowledge techniques; security attacks; software products; HTML; Security; XML; DTD: Document Type Definition; DoS: Denial of service; HTTP: Hyper Text Transfer Protocol; SMTP: Simple Mail Transfer Protocol; SOAP: Simple Object Access Protocol; XHTML: extensible Hypertext Markup Language; XML Schema; XML injection; XML: Extensible Markup Language;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Software and Networks (ICCSN), 2011 IEEE 3rd International Conference on
  • Conference_Location
    Xi´an
  • Print_ISBN
    978-1-61284-485-5
  • Type

    conf

  • DOI
    10.1109/ICCSN.2011.6014015
  • Filename
    6014015