DocumentCode
584812
Title
Object oriented approach to SQL injection preventer
Author
Giri, D.R. ; Kumar, Sathiya Prabhu ; Prasannakumar, L. ; Murthy, R.N.V.V.
Author_Institution
Dept. of IT, SRKR Eng. Coll., Bhimavaram, India
fYear
2012
fDate
26-28 July 2012
Firstpage
1
Lastpage
7
Abstract
Many web applications can be exposed to a variety of Web-based attacks. One of these attacks is SQL injection, which can give attackers unrestricted access to the databases and has become increasingly frequent and serious. This paper presents a new highly automated approach for protecting Web applications against SQL injection that has both theoretical and practical advantages over most existing techniques. From a theoretical view, the approach is based on the idea of positive tainting and on the concept of syntax-aware evaluation. From a practical view, our technique is efficient, has minimal deployment requirements, and has a negligible performance overhead in most cases. We have implemented our techniques in the Web Application SQL-injection Preventer (WASP) tool, where a wide range of Web applications were subjected to a large and varied set of attacks and legal accesses. We considered login validation of user in an online banking system. WASP was able to stop all of these attacks and did not generate any false positives.
Keywords
Internet; SQL; object-oriented programming; security of data; WASP; Web application SQL injection preventer; Web based attacks; database access; object oriented approach; syntax aware evaluation; Computer architecture; Servers; Software; Injection; SQL; WASP;
fLanguage
English
Publisher
ieee
Conference_Titel
Computing Communication & Networking Technologies (ICCCNT), 2012 Third International Conference on
Conference_Location
Coimbatore
Type
conf
DOI
10.1109/ICCCNT.2012.6395979
Filename
6395979
Link To Document