Encoding Query Based Lightweight Algorithm for Preventing SQL injection attack.

SQL injection attacks are still common issue in web applications. Although different techniques have been proposed to prevent SQL injection attack, it has a high impact on web applications, especially associated with large and sensitive databases. In this attack, an attacker can inject malicious cod...

Descripción completa

Detalles Bibliográficos
Publicado en:Journal of Basrah Researches (Sciences) Vol. 46; no. 1; pp. 1 - 12
Autores principales: Shwaish, Alaa Khudhair, Hussain, Mohammed Abdulridha, Al-Kashoash, Hayder A. A.
Formato: Artículo
Publicado: Republic of Iraq Ministry of Higher Education & Scientific Research (MOHESR) 2020
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=151790514&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 151790514
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        18172695
        GYGY
      jtl: Journal of Basrah Researches (Sciences)
      issn: 18172695
      maglogo: N
    pubinfo:
      dt: 2020
      vid: 46
      iid: 1
      pid: 25427
      pub: Republic of Iraq Ministry of Higher Education & Scientific Research (MOHESR)
    artinfo:
      ui: 151790514
      ppf: 1
      ppct: 11
      formats:
      tig:
        atl: Encoding Query Based Lightweight Algorithm for Preventing SQL injection attack.
      aug:
        au:
          Shwaish, Alaa Khudhair
          Hussain, Mohammed Abdulridha
          Al-Kashoash, Hayder A. A.
        affil: Computer Science Department, Education College for pure Science, University of Basrah, Basrah, Iraq. Computer Systems Technical Department, Technical Institute/ Qurna, Southern Technical University, Basrah, 2 Iraq.
      su:
        SQL
        Denial of service attacks
        Web-based user interfaces
        Algorithms
        Data entry
      sug:
        subj:
          SQL
          Denial of service attacks
          Web-based user interfaces
          Algorithms
          Data entry
      keyword:
        ترميز االستعالم
        حركة مر ور HTTP
        حقن SQL
        نقاط الضعف
        Comment
        Encoding Query
        HTTP traffic
        Piggybacked
        SQL injection
        Tautology
        Vulnerabilities
        ترميز االستعالم
        حركة مر ور HTTP
        حقن SQL
        نقاط الضعف
      ab: SQL injection attacks are still common issue in web applications. Although different techniques have been proposed to prevent SQL injection attack, it has a high impact on web applications, especially associated with large and sensitive databases. In this attack, an attacker can inject malicious code into the data entry field of the input form and bypass authentication, access, then modification and deletion of data within the database. In this paper, a lightweight algorithm is introduced based on encoding of the query named (EQA) considering HTTP traffic parameters e.g. request and response time and message length. EQA hides the SQL relationship with the database, and prevents some common types of SQL injection (Tautology, Piggybacked and Comment). EQA is implemented and tested using MySQL and PHP environment and Wireshark platform. The results demonstrate that the proposal has a good performance in terms of security level, reducing HTTP request and response time and message length.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2020
    holdings:
      @attributes:
        islocal: N