Analysis and classification of SQL injection vulnerabilities and attacks on web applications

Chandershekhar Sharma, S. C. Jain
{"title":"Analysis and classification of SQL injection vulnerabilities and attacks on web applications","authors":"Chandershekhar Sharma, S. C. Jain","doi":"10.1109/ICAETR.2014.7012815","DOIUrl":null,"url":null,"abstract":"Web applications interact with the back-end database to retrieve data as and when requested by the user. Web applications (Like e-commerce, banking, shopping, trading, blogs etc.) are the backbone of today's online business industry. For activities like paying of bills & merchandize information must be kept safe with these web applications but unfortunately there is no guarantee of integrity and confidentially of information. The global exposure of these applications makes them prone to the attacks because of presence of vulnerabilities. These security vulnerabilities continue to infect the web applications through injection attacks. SQL injection attacks (SQLIA's) are one of the top most threat in database centric web application and SQL injections vulnerabilities(SQLIV's) are the most serious Vulnerability types.SQLIA allows the attacker to gain control over the database of an application resulting in financial fraud, Leak of confidential data, network hacking, deleting database, theft and many more to count. In this paper we have discussed the classification of SQL injection attacks and also analysis is done on basis of risk associated with each attack.","PeriodicalId":196504,"journal":{"name":"2014 International Conference on Advances in Engineering & Technology Research (ICAETR - 2014)","volume":"34 2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"33","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Advances in Engineering & Technology Research (ICAETR - 2014)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICAETR.2014.7012815","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 33

Abstract

Web applications interact with the back-end database to retrieve data as and when requested by the user. Web applications (Like e-commerce, banking, shopping, trading, blogs etc.) are the backbone of today's online business industry. For activities like paying of bills & merchandize information must be kept safe with these web applications but unfortunately there is no guarantee of integrity and confidentially of information. The global exposure of these applications makes them prone to the attacks because of presence of vulnerabilities. These security vulnerabilities continue to infect the web applications through injection attacks. SQL injection attacks (SQLIA's) are one of the top most threat in database centric web application and SQL injections vulnerabilities(SQLIV's) are the most serious Vulnerability types.SQLIA allows the attacker to gain control over the database of an application resulting in financial fraud, Leak of confidential data, network hacking, deleting database, theft and many more to count. In this paper we have discussed the classification of SQL injection attacks and also analysis is done on basis of risk associated with each attack.
web应用中SQL注入漏洞和攻击的分析与分类
Web应用程序与后端数据库交互,以便在用户请求时检索数据。Web应用程序(如电子商务、银行、购物、交易、博客等)是当今在线商业行业的支柱。对于像支付账单和商品信息这样的活动,这些网络应用程序必须保持安全,但不幸的是,没有保证信息的完整性和机密性。由于存在漏洞,这些应用程序的全局暴露使它们容易受到攻击。这些安全漏洞通过注入攻击继续感染web应用程序。SQL注入攻击(SQLIA)是以数据库为中心的web应用中最严重的威胁之一,而SQL注入漏洞(SQLIV)是最严重的漏洞类型。SQLIA允许攻击者获得对应用程序数据库的控制,从而导致财务欺诈、机密数据泄漏、网络黑客攻击、删除数据库、盗窃等等。在本文中,我们讨论了SQL注入攻击的分类,并分析了与每种攻击相关的风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信