Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Semi-Automated Verification of Defense against SQL Injection in Web Applications
Liu, Kaiping; Tan, Hee Beng Kuan; Shar, Lwin Khin
2012In APSEC
Peer reviewed
 

Files


Full Text
Semi-Automated Verification of Defense against SQL Injection in Web Applications_APSEC12.pdf
Publisher postprint (216.16 kB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
SQL injection; Vulnerabilities; Code auditing
Abstract :
[en] Recent reports reveal that majority of the attacks to Web applications are input manipulation attacks. Among these attacks, SQL injection attack – malicious input is submitted to manipulate the database in a way that was unintended by the applications' developers – is one such attack. This paper proposes an approach for assisting to code verification process on the defense against SQL injection. The approach extracts all such defenses implemented in code. With the use of the proposed approach, developers, testers or auditors can then check the defenses extracted from code to verify their adequacy. We have evaluated the feasibility, effectiveness, and usefulness of the proposed approach by a set of open-source systems. Our experiment results showed that the proposed approach is effective in extracting all the possible defenses implemented/adopted by Web applications. We observed that the proposed approach would be useful in identifying the false positive cases resulting from other related approaches and auditing the code in order to fix the actual vulnerable cases.
Disciplines :
Computer science
Author, co-author :
Liu, Kaiping;  Nanyang Technological University > Information Engineering
Tan, Hee Beng Kuan;  Nanyang Technological University > Information Engineering
Shar, Lwin Khin ;  Nanyang Technological University > Information Engineering
External co-authors :
yes
Language :
English
Title :
Semi-Automated Verification of Defense against SQL Injection in Web Applications
Publication date :
2012
Event name :
19th Asia-Pacific Software Engineering Conference
Event date :
04-12-2012 to 07-12-2012
Audience :
International
Main work title :
APSEC
Peer reviewed :
Peer reviewed
Commentary :
91-96
Available on ORBilu :
since 24 June 2014

Statistics


Number of views
75 (8 by Unilu)
Number of downloads
0 (0 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
WoS citations
 
0

Bibliography


Similar publications



Contact ORBilu