Fu Xiao, Wang Zhi-jian, Wang Meiling, Chen Ning, Zhu Yue, Zhang Lei, Wang Pei, Cao Xiaoning
{"title":"新时代的老风险:云环境中的SQL注入","authors":"Fu Xiao, Wang Zhi-jian, Wang Meiling, Chen Ning, Zhu Yue, Zhang Lei, Wang Pei, Cao Xiaoning","doi":"10.1504/ijguc.2021.10034610","DOIUrl":null,"url":null,"abstract":"After haunting all the software engineers for more than 26 years since it was discovered and classified in 2002, SQL injection still poses a most serious threat to developers, maintainers and users of web applications even into the brand new cloud era. SaaS, PaaS and IaaS virtualisation technologies which are widely used by cloud computing seemed to fail the enhancement of security against such an attack. We strive to study the mechanism and principles of SQL injection attack in order to help the information security personnel to understand and manage such risks.","PeriodicalId":44878,"journal":{"name":"International Journal of Grid and Utility Computing","volume":"1 1","pages":""},"PeriodicalIF":0.5000,"publicationDate":"2021-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"An old risk in the new era: SQL injection in cloud environment\",\"authors\":\"Fu Xiao, Wang Zhi-jian, Wang Meiling, Chen Ning, Zhu Yue, Zhang Lei, Wang Pei, Cao Xiaoning\",\"doi\":\"10.1504/ijguc.2021.10034610\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"After haunting all the software engineers for more than 26 years since it was discovered and classified in 2002, SQL injection still poses a most serious threat to developers, maintainers and users of web applications even into the brand new cloud era. SaaS, PaaS and IaaS virtualisation technologies which are widely used by cloud computing seemed to fail the enhancement of security against such an attack. We strive to study the mechanism and principles of SQL injection attack in order to help the information security personnel to understand and manage such risks.\",\"PeriodicalId\":44878,\"journal\":{\"name\":\"International Journal of Grid and Utility Computing\",\"volume\":\"1 1\",\"pages\":\"\"},\"PeriodicalIF\":0.5000,\"publicationDate\":\"2021-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Grid and Utility Computing\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1504/ijguc.2021.10034610\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Grid and Utility Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1504/ijguc.2021.10034610","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
An old risk in the new era: SQL injection in cloud environment
After haunting all the software engineers for more than 26 years since it was discovered and classified in 2002, SQL injection still poses a most serious threat to developers, maintainers and users of web applications even into the brand new cloud era. SaaS, PaaS and IaaS virtualisation technologies which are widely used by cloud computing seemed to fail the enhancement of security against such an attack. We strive to study the mechanism and principles of SQL injection attack in order to help the information security personnel to understand and manage such risks.