Prevention of SQL Injection Attacks using Query Hashing Technique

Yash Swarup, Anuj Kumar, A. Tyagi, Vimal Kumar
{"title":"Prevention of SQL Injection Attacks using Query Hashing Technique","authors":"Yash Swarup, Anuj Kumar, A. Tyagi, Vimal Kumar","doi":"10.1109/ICORT52730.2021.9581804","DOIUrl":null,"url":null,"abstract":"Web applications are a vital part of day-to-day life. Many critical services like shopping, health, banking, data communication and transport are partly or completely dependent on the Internet. Simultaneously, different kinds of the attacks in the network are introduced by various kinds of attacker. One of the important security attacks is SQL injection. It is a web application vulnerability by which an attacker can get unauthorized access to the database of a website. With the help of SQL injection an attacker can take control of any website if attacker is able to get the credentials of the administrator of the website. In some cases, an attacker may access, delete or modify the data in the database that may cause permanent changes in the applications' content or behavior. In this paper, we have proposed a new technique to prevent SQL Injection attacks by comparing the hash value of the generated query with the hashed value of the legitimate query. Our scheme can be easily added to any prebuilt website build using any language or database type as it requires only few changes to be made in the code of the language.","PeriodicalId":344816,"journal":{"name":"2021 2nd International Conference on Range Technology (ICORT)","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-08-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 2nd International Conference on Range Technology (ICORT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICORT52730.2021.9581804","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Web applications are a vital part of day-to-day life. Many critical services like shopping, health, banking, data communication and transport are partly or completely dependent on the Internet. Simultaneously, different kinds of the attacks in the network are introduced by various kinds of attacker. One of the important security attacks is SQL injection. It is a web application vulnerability by which an attacker can get unauthorized access to the database of a website. With the help of SQL injection an attacker can take control of any website if attacker is able to get the credentials of the administrator of the website. In some cases, an attacker may access, delete or modify the data in the database that may cause permanent changes in the applications' content or behavior. In this paper, we have proposed a new technique to prevent SQL Injection attacks by comparing the hash value of the generated query with the hashed value of the legitimate query. Our scheme can be easily added to any prebuilt website build using any language or database type as it requires only few changes to be made in the code of the language.
利用查询哈希技术防止SQL注入攻击
Web应用程序是日常生活的重要组成部分。许多关键服务,如购物、医疗、银行、数据通信和运输,部分或完全依赖于互联网。同时,不同类型的攻击者在网络中引入了不同类型的攻击。SQL注入是一种重要的安全攻击。这是一个web应用程序漏洞,攻击者可以通过该漏洞未经授权访问网站的数据库。在SQL注入的帮助下,攻击者可以控制任何网站,如果攻击者能够获得网站管理员的凭据。在某些情况下,攻击者可能会访问、删除或修改数据库中的数据,从而导致应用程序的内容或行为发生永久性变化。在本文中,我们提出了一种通过比较生成查询的哈希值与合法查询的哈希值来防止SQL注入攻击的新技术。我们的方案可以很容易地添加到使用任何语言或数据库类型的任何预构建网站构建,因为它只需要在语言的代码中进行很少的更改。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信