SQLPIL: SQL injection prevention by input labeling

Wes Masri, Sam Sleiman · Security and Communication Networks · 2015

Abstract SQL injection attacks(SQLIAs) aim at exploiting vulnerabilities in web applications in order to execute malicious SQL commands. It is established thatprepared statementsare resilient to SQLIAs, and thus, developers are advised to use them when constructing SQL queries as opposed to applying string concatenation operations. Unfortunately, this recommended programming practice is not as pervasive as it should be. This paper addresses this shortcoming by presentingSQL injection Prevention by Input Labeling(SQLPIL), an effective, light, and fully automated tool that leverages prepared statements topreventSQLIAs at runtime. Given a Java program in which SQL queries are built as strings,SQLPILdynamically transforms the strings into secure prepared statements right before their execution, thus guaranteeing that malicious input will always be treated as data and never as SQL commands. We empirically evaluated our Java implementation ofSQLPILusing a benchmark that includes five JSP commercial applications, a number of legitimate queries, and a number of attacks of representative types. The results were promising as all attacks were prevented, and all legitimate runs executed successfully; in other words, the technique exhibitedno false alarmswhen applied on typical applications. Also, the runtime cost was acceptable, assuming typical settings. Copyright © 2015 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik