{"title":"Detection and Analysis of Attacks Against Web Services by the SQL Injection Method","authors":"Ilker Kara, M. Aydos","doi":"10.1109/ISMSIT.2019.8932755","DOIUrl":null,"url":null,"abstract":"SQL injection is a security vulnerability resulting from unauthorized access to the victim database and services by attackers. Harmful codes can be injected into the victim database, all information in the database can be accessed or the database can be deleted completely and rendered unusable by using the SQL injection method. SQL injection attacks are a simple and effective method, used frequently in hacking attacks against Web services. Despite all measures taken, SQL injection attacks continue to increase. The academic studies in this field are usually theoretical, having limited practical aspects. In this study, an SQL injection attack case against a web service was examined in detail. The study aims to evaluate the SQL injection attacks in practice.","PeriodicalId":169791,"journal":{"name":"2019 3rd International Symposium on Multidisciplinary Studies and Innovative Technologies (ISMSIT)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 3rd International Symposium on Multidisciplinary Studies and Innovative Technologies (ISMSIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISMSIT.2019.8932755","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
SQL injection is a security vulnerability resulting from unauthorized access to the victim database and services by attackers. Harmful codes can be injected into the victim database, all information in the database can be accessed or the database can be deleted completely and rendered unusable by using the SQL injection method. SQL injection attacks are a simple and effective method, used frequently in hacking attacks against Web services. Despite all measures taken, SQL injection attacks continue to increase. The academic studies in this field are usually theoretical, having limited practical aspects. In this study, an SQL injection attack case against a web service was examined in detail. The study aims to evaluate the SQL injection attacks in practice.