Protecting web applications from SQL injection attacks by using framework and database firewall
Yakkala V. Naga Manikanta, Anjali Sardana · 2012
SQL Injection attacks are the costly and critical attacks on web applications: it is a code injection technique that allows attackers to obtain unrestricted access to the databases and potentially sensitive information like usernames, passwords, email ids, credit card details present in them. Various techniques have been proposed to address the problem of SQL Injection attack such as defense coding practices, detection and prevention techniques, and intrusion detection systems. However most of these techniques have one or more disadvantages such as requirement for code modification, applicable to limited type of attacks and web applications. In this paper, we discuss a secure mechanism for protecting web applications from SQL Injection attacks by using framework and database firewall. This mechanism uses combined static and dynamic analysis technique. In static analysis, we list URLs, forms, injection points, and vulnerable parameters of web application. Thus, we identify valid queries that could be generated by the application. In dynamic analysis, we use database firewall to monitor runtime generated queries and check them against the whitelist of queries. The experimental setup makes use of real web applications and two open source tools namely Web Application Attack and Audit Framework (w3af) and GreenSQL. We used w3af for listing all the valid queries and GreenSQL as database firewall. The results show that implemented mechanism is capable of detecting all types of SQL Injection attacks without requiring any code modification to the existing web application but with an additional element of deploying a proxy.