Back to Search Start Over

Defeating SQL injection attack in authentication security: an experimental study.

Authors :
Das, Debasish
Sharma, Utpal
Bhattacharyya, D. K.
Source :
International Journal of Information Security. Feb2019, Vol. 18 Issue 1, p1-22. 22p.
Publication Year :
2019

Abstract

Whenever web-application executes dynamic SQL statements it may come under SQL injection attack. To evaluate the existing practices of its detection, we consider two different security scenarios for the web-application authentication that generates dynamic SQL query with the user input data. Accordingly, we generate two different datasets by considering all possible vulnerabilities in the run-time queries. We present proposed approach based on edit-distance to classify a dynamic SQL query as normal or malicious using web-profile prepared with the dynamic SQL queries during training phase. We evaluate the dataset using proposed approach and some well-known supervised classification approaches. Our proposed method is found more effective in detecting SQL injection attack under both the scenarios of authentication security. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
16155262
Volume :
18
Issue :
1
Database :
Academic Search Index
Journal :
International Journal of Information Security
Publication Type :
Academic Journal
Accession number :
134195909
Full Text :
https://doi.org/10.1007/s10207-017-0393-x