Efficient Method for Preventing SQL Injection Attacks on Web Applications Using Encryption and Tokenization
P. Saravana kumar, M. Parvathi, M. Kanmani · 2014
Web applications are increasingly used in recent years to provide online services such as banking, shopping, social networking, etc. These applications operate with sensitive user information and hence there is a high need for assuring their confidentiality, integrity, and availability. The proposed system focuses on how to detect and prevent SQL injection attacks on web applications using encryption and tokenization technique. The tokenization process is applied on the input query by detecting spaces, single quotes and double dashes etc. This process converts the input query into fruitful tokens on both client and server side and that are stored in a dynamic tables. Both dynamic tables are compared and if both are equal, it seems that there is no injection attacked in the given query, hence the query is proceed further to main database for retrieving result. If they are different, query is rejected and not forwarded to the database server. The Customized error message notification is given to the client. It has better performance and provides increased security in comparison to the existing solutions. The goal of this project is to provide increased security by developing a method which prevents illegal access to the database.