A combined approach to prevent SQL Injection Attacks
Evans Dogbe, Richard Charles Millham, Prenitha Singh · Science and Information Conference · 2013
In order to adapt to changing business requirements, information systems are often migrated to the Web but, in doing so, these systems often have their security vulnerabilities exposed to a wider range of attacks. One of the most prominent type of security attacks faced by these systems, according to Mitre Corporation, are SQL Injection Attacks (SQLIA). In this paper, we examine different approaches to detect and protect against SQLIA, each with their strengths and weaknesses, and then propose a combined approach of SQLIA prevention techniques (the fine grained Role Based Access Control [RBAC] and static and dynamic analysis of SQL parse trees) in order to maximise the advantages of each method and to ensure that a second line of defence is provided, in case the first method fails.