On Defense and Detection of SQL SERVER Injection Attack

Qian Xue, Peng He · 2011

The mechanism of SQL injection attack is introduced in this paper. Differing from the works of the predecessors, the authors categorize the injection attacks according to the characteristics of the injection codes. For the type of web databases with SQL Server as the backend, a DDL (Detection-Defense-Log) Model against SQL injection is created. Both the client computer and the server are included in the model. The model is intended to prevent as many attacks as possible and record the dangerous attack actions by deploying some smart program on the client computer and the server respectively, which can check the length and data type of the submitted variables, and detect the injection-sensitive characters and keywords.

Read the paper · More papers on PaperTik