Encoding Query Based Lightweight Algorithm for Preventing SQL injection attack.
SQL injection attacks are still common issue in web applications. Although different techniques have been proposed to prevent SQL injection attack, it has a high impact on web applications, especially associated with large and sensitive databases. In this attack, an attacker can inject malicious cod...
| Publicado en: | Journal of Basrah Researches (Sciences) Vol. 46; no. 1; pp. 1 - 12 |
|---|---|
| Autores principales: | , , |
| Formato: | Artículo |
| Publicado: |
Republic of Iraq Ministry of Higher Education & Scientific Research (MOHESR)
2020
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=151790514&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 151790514 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 18172695 GYGY jtl: Journal of Basrah Researches (Sciences) issn: 18172695 maglogo: N pubinfo: dt: 2020 vid: 46 iid: 1 pid: 25427 pub: Republic of Iraq Ministry of Higher Education & Scientific Research (MOHESR) artinfo: ui: 151790514 ppf: 1 ppct: 11 formats: tig: atl: Encoding Query Based Lightweight Algorithm for Preventing SQL injection attack. aug: au: Shwaish, Alaa Khudhair Hussain, Mohammed Abdulridha Al-Kashoash, Hayder A. A. affil: Computer Science Department, Education College for pure Science, University of Basrah, Basrah, Iraq. Computer Systems Technical Department, Technical Institute/ Qurna, Southern Technical University, Basrah, 2 Iraq. su: SQL Denial of service attacks Web-based user interfaces Algorithms Data entry sug: subj: SQL Denial of service attacks Web-based user interfaces Algorithms Data entry keyword: ترميز االستعالم حركة مر ور HTTP حقن SQL نقاط الضعف Comment Encoding Query HTTP traffic Piggybacked SQL injection Tautology Vulnerabilities ترميز االستعالم حركة مر ور HTTP حقن SQL نقاط الضعف ab: SQL injection attacks are still common issue in web applications. Although different techniques have been proposed to prevent SQL injection attack, it has a high impact on web applications, especially associated with large and sensitive databases. In this attack, an attacker can inject malicious code into the data entry field of the input form and bypass authentication, access, then modification and deletion of data within the database. In this paper, a lightweight algorithm is introduced based on encoding of the query named (EQA) considering HTTP traffic parameters e.g. request and response time and message length. EQA hides the SQL relationship with the database, and prevents some common types of SQL injection (Tautology, Piggybacked and Comment). EQA is implemented and tested using MySQL and PHP environment and Wireshark platform. The results demonstrate that the proposal has a good performance in terms of security level, reducing HTTP request and response time and message length. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2020 holdings: @attributes: islocal: N |
|---|