• DocumentCode
    3537695
  • Title

    Effective SQL Injection Attack Reconstruction Using Network Recording

  • Author

    Pomeroy, Allen ; Tan, Qing

  • Author_Institution
    Sch. of Comput. & Inf. Syst., Athabasca Univ., Athabasca, AB, Canada
  • fYear
    2011
  • fDate
    Aug. 31 2011-Sept. 2 2011
  • Firstpage
    552
  • Lastpage
    556
  • Abstract
    Web applications offer business and convenience services that society has become dependent on, such as online banking. Success of these applications is dependent on end user trust, although these services have serious weaknesses that can be exploited by attackers. Application owners must take additional steps to ensure the security of customer data and integrity of the applications, since web applications are under siege from cyber criminals seeking to steal confidential information and disable or damage the services offered by these applications. Successful attacks have lead to some organizations experiencing financial difficulties or even being forced out of business. Organizations have insufficient tools to detect and respond to attacks on web applications, since traditional security logs have gaps that make attack reconstruction nearly impossible. This paper explores network recording challenges, benefits and possible future use. A network recording solution is proposed to detect and capture SQL injection attacks, resulting in the ability to successfully reconstruct SQL injection attacks in order to maintain application integrity.
  • Keywords
    Internet; SQL; banking; financial management; organisational aspects; security of data; SQL injection attack reconstruction; Web application; attack reconstruction; cyber criminals; data security; network recording; online banking; security logs; web applications; Business; Databases; Forensics; Payloads; Security; USA Councils; Web servers; Bro-IDS; SQL injection attacks; digital evidence; intrusion detection; network recording; time machine;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology (CIT), 2011 IEEE 11th International Conference on
  • Conference_Location
    Pafos
  • Print_ISBN
    978-1-4577-0383-6
  • Electronic_ISBN
    978-0-7695-4388-8
  • Type

    conf

  • DOI
    10.1109/CIT.2011.103
  • Filename
    6036824