Please use this identifier to cite or link to this item:
https://rda.sliit.lk/handle/123456789/2558
Title: | Identification and Mitigation Tool for Sql Injection Attacks(SQLIA) |
Authors: | Rankothge, W. H Randeniya, M Samaranayaka, V |
Keywords: | Identification Mitigation Tool Sql Injection Attacks (SQLIA) Attacks (SQLIA) |
Issue Date: | 26-Nov-2020 |
Publisher: | IEEE |
Citation: | W. H. Rankothge, M. Randeniya and V. Samaranayaka, "Identification and Mitigation Tool for Sql Injection Attacks (SQLIA)," 2020 IEEE 15th International Conference on Industrial and Information Systems (ICIIS), 2020, pp. 591-595, doi: 10.1109/ICIIS51140.2020.9342703. |
Series/Report no.: | 2020 IEEE 15th International Conference on Industrial and Information Systems (ICIIS); |
Abstract: | Structured Query Language Injection Attack (SQLIA) is a very frequent web security vulnerability. The attacker adds a malicious Structured Query Language (SQL) code to the input field of a web form, so that he can gain access to data or make unauthorized changes to data. A successful malicious SQL injection cause serious consequence to the victimized organization such as financial loss, reputation loss, compliance, and regulatory breaches. There have been several research works on detection and prevention of SQL injection attacks. However, still there is an absence of an advanced single tools for both identification and mitigation of SQL injection attacks. We have proposed an approach to identify and mitigate SQL injection attacks using a single tool and it allows software testers to identify the SQL injection vulnerabilities of their web applications during the testing stages. The proposed approach is based on parameterized queries and user input validation. Our results show that the tool provides 100% accurate and efficient results on identification and mitigation of SQL vulnerabilities. |
URI: | http://rda.sliit.lk/handle/123456789/2558 |
ISSN: | 2164-7011 |
Appears in Collections: | Department of Computer Systems Engineering-Scopes Research Papers - Dept of Computer Systems Engineering Research Papers - IEEE Research Papers - SLIIT Staff Publications |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
Identification_and_Mitigation_Tool_for_Sql_Injection_Attacks_SQLIA.pdf Until 2050-12-31 | 113.17 kB | Adobe PDF | View/Open Request a copy |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.