A combined approach to prevent SQL Injection Attacks

Evans Dogbe, Richard Charles Millham, Prenitha Singh · Science and Information Conference · 2013

In order to adapt to changing business requirements, information systems are often migrated to the Web but, in doing so, these systems often have their security vulnerabilities exposed to a wider range of attacks. One of the most prominent type of security attacks faced by these systems, according to Mitre Corporation, are SQL Injection Attacks (SQLIA). In this paper, we examine different approaches to detect and protect against SQLIA, each with their strengths and weaknesses, and then propose a combined approach of SQLIA prevention techniques (the fine grained Role Based Access Control [RBAC] and static and dynamic analysis of SQL parse trees) in order to maximise the advantages of each method and to ensure that a second line of defence is provided, in case the first method fails.

Read the paper · More papers on PaperTik