• DocumentCode
    693696
  • Title

    Reverse proxy framework using sanitization technique for intrusion prevention in database

  • Author

    Randhe, Vrushali S. ; Chougule, Archana B. ; Mukhopadhyay, Debdeep

  • Author_Institution
    Dept. of Inf. Technol., Maharashtra Inst. of Technol., Pune, India
  • fYear
    2013
  • fDate
    18-19 Oct. 2013
  • Firstpage
    200
  • Lastpage
    208
  • Abstract
    With the increasing importance of the internet in our day-to-day life, data security in web application has become very crucial. Ever increasing online and real time transaction services have led to manifold rise in the problems associated with the database security. Attacker uses illegal and unauthorized approaches to hijack the confidential information like username, password and other vital details. Hence the real-time transaction requires security against web based attacks. SQL injection and cross site scripting attack are the most common application layer attack. The SQL injection attacker pass SQL statement through a web application´s input fields, URL or hidden parameters and get access to the database or update it. The attacker take a benefit from user provided data in such a way that the user´s input is handled as a SQL code. Using this vulnerability an attacker can execute SQL commands directly on the database. SQL injection attacks are most serious threats which take user´s input and integrate it into SQL query. Reverse Proxy is a technique which is used to sanitize the users´ inputs that may transform into a database attack. In this technique a data redirector program redirects the user´s input to the proxy server before it is sent to the application server. At the proxy server, data cleaning algorithm is triggered using a sanitizing application. In this framework we include detection and sanitization of the tainted information being sent to the database and innovate a new prototype.
  • Keywords
    Internet; SQL; database management systems; query processing; security of data; Internet; SQL code; SQL injection attacker; SQL query; SQL statement; URL; Web application; Web based attacks; application layer attack; confidential information; cross site scripting attack; data redirector program; data security; database attack; database security; illegal approaches; intrusion prevention; proxy server; real-time transaction; reverse proxy framework; sanitization technique; transaction services; unauthorized approaches; Cross Site Scripting Attack; Data Sanitization; Database Security; SQL Attack; SQL Injection; Security Threats;
  • fLanguage
    English
  • Publisher
    iet
  • Conference_Titel
    Computational Intelligence and Information Technology, 2013. CIIT 2013. Third International Conference on
  • Conference_Location
    Mumbai
  • Type

    conf

  • DOI
    10.1049/cp.2013.2592
  • Filename
    6950876