A Hot Query Bank approach to improve detection performance against SQL injection attacks

Yu-Chi Chung, Ming-Chuan Wu, Yih-Chang Chen, Wen-Kui Chang

Computers & Security(2012)

引用 16|浏览7
暂无评分
摘要
SQL injection attacks (SQLIAs) exploit web sites by altering backend SQL statements through manipulating application input. With the growing popularity of web applications, such attacks have become a serious security threat to users and systems as well. Existing dynamic SQLIA detectors provide high detection accuracy yet may have ignored another focus: efficiency. Our research has found that inside most systems exist many hot queries that current SQLIA detectors have repeatedly verified. Such repetition causes unnecessary waste of system resources.
更多
查看译文
关键词
Web applications,Security,SQL injection attacks,Hot query,Bloom filter,SQLIA detectors
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要