The SQL Injection Attacking Prevention Applying the Design Techniques of IPTABLES
Preecha Noiumkar - · Journal of Convergence Information Technology · 2012
This study presents the SQL Injection Prevention using the design techniques of IPTABLES. It applied the IPTABLES’s special feature that is able to investigate the application layers to detect and drop the packets that contains SQL patterns ( e.g. ' or '1'=' ). Besides, the study suggests the methods for designing the IPTABLES rule without a confliction or that has least possibility of confliction between the rules. The researcher presents how to adjust IPTABLES to filter the SQL Injection packets more rapidly by applying the concept of relation and Cartesian product into designing the rule and using the rule repositioning method. The researcher has also collected various patterns that used to be attacked with SQL Injection, from different reliable sources, to find out the common signatures. Then these patterns were concluded to be about 10 patterns only so that they would function with least overhead. In addition, the researcher has run the performance testing and found that the response time has been slightly increased, while the possibility of false positive appeared at an acceptable rate.