Skip to main content
Top
Published in: International Journal of Information Security 1/2019

07-11-2017 | Regular Contribution

Defeating SQL injection attack in authentication security: an experimental study

Authors: Debasish Das, Utpal Sharma, D. K. Bhattacharyya

Published in: International Journal of Information Security | Issue 1/2019

Log in

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Whenever web-application executes dynamic SQL statements it may come under SQL injection attack. To evaluate the existing practices of its detection, we consider two different security scenarios for the web-application authentication that generates dynamic SQL query with the user input data. Accordingly, we generate two different datasets by considering all possible vulnerabilities in the run-time queries. We present proposed approach based on edit-distance to classify a dynamic SQL query as normal or malicious using web-profile prepared with the dynamic SQL queries during training phase. We evaluate the dataset using proposed approach and some well-known supervised classification approaches. Our proposed method is found more effective in detecting SQL injection attack under both the scenarios of authentication security.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Appendix
Available only for authorised users
Literature
1.
go back to reference MITRE/SANS: A vulnerability report. In: Top 25 most Dangerous Software Errors, MITRE Corporation Inc. (2011) MITRE/SANS: A vulnerability report. In: Top 25 most Dangerous Software Errors, MITRE Corporation Inc. (2011)
3.
go back to reference Shar, L., Tan, H.B.K.: Defeating SQL injection. IEEE Comput. J. Mag. 46(3), 69–77 (2013)CrossRef Shar, L., Tan, H.B.K.: Defeating SQL injection. IEEE Comput. J. Mag. 46(3), 69–77 (2013)CrossRef
4.
go back to reference Su, Z., Wassermann, G.: The essence of command injection attacks in web application. In: In the 33rd Annual Symposium on Principles of Programming Languages, pp. 372–382 (2006) Su, Z., Wassermann, G.: The essence of command injection attacks in web application. In: In the 33rd Annual Symposium on Principles of Programming Languages, pp. 372–382 (2006)
5.
go back to reference Bisht, P., Madhusudan, P., Venkatakrishnan, V.N.: Dynamic candidate evaluations for automatic prevention of SQL injection attacks. ACM Trans. Inf. Syst. Secur. 13(14), 14–38 (2010) Bisht, P., Madhusudan, P., Venkatakrishnan, V.N.: Dynamic candidate evaluations for automatic prevention of SQL injection attacks. ACM Trans. Inf. Syst. Secur. 13(14), 14–38 (2010)
11.
go back to reference Halfond, W.G., Orso, A., Manolios, P.: Using positive tainting and syntax-aware evaluation to counter SQL injection attacks. In: SIGSOFT’06/FSE-14, Portland Oregon, USA, ACM Digital Library, pp. 175–185 (2006) Halfond, W.G., Orso, A., Manolios, P.: Using positive tainting and syntax-aware evaluation to counter SQL injection attacks. In: SIGSOFT’06/FSE-14, Portland Oregon, USA, ACM Digital Library, pp. 175–185 (2006)
13.
go back to reference Pop, I.: An approach of the Naive Bayes classifier for the document classification. Gen. Math. 14(4), 135138 (2006)MathSciNet Pop, I.: An approach of the Naive Bayes classifier for the document classification. Gen. Math. 14(4), 135138 (2006)MathSciNet
14.
go back to reference John, G.H., Langley, P.: Estimating continuous distributions in Bayesian classifiers. In: UAI’95 Proceedings of the Eleventh Conference on Uncertainty in Artificial Intelligence (1995) John, G.H., Langley, P.: Estimating continuous distributions in Bayesian classifiers. In: UAI’95 Proceedings of the Eleventh Conference on Uncertainty in Artificial Intelligence (1995)
15.
go back to reference Cortes, C., Vapnik, V.: Support-vector networks. Mach. Learn. 20, 273–297 (1995)MATH Cortes, C., Vapnik, V.: Support-vector networks. Mach. Learn. 20, 273–297 (1995)MATH
18.
go back to reference Kang, J., Kim, J., Park, C., Park, H., Lee, J.: A multi channel architecture for high-performance nand flash-based storage system. J. Syst. Arch. 53(9), 644–658 (2007) Kang, J., Kim, J., Park, C., Park, H., Lee, J.: A multi channel architecture for high-performance nand flash-based storage system. J. Syst. Arch. 53(9), 644–658 (2007)
Metadata
Title
Defeating SQL injection attack in authentication security: an experimental study
Authors
Debasish Das
Utpal Sharma
D. K. Bhattacharyya
Publication date
07-11-2017
Publisher
Springer Berlin Heidelberg
Published in
International Journal of Information Security / Issue 1/2019
Print ISSN: 1615-5262
Electronic ISSN: 1615-5270
DOI
https://doi.org/10.1007/s10207-017-0393-x

Other articles of this Issue 1/2019

International Journal of Information Security 1/2019 Go to the issue

Premium Partner