Research of the Active Defense Technology for the SQL Server Injection Attack
Haiwei Li · 2012
In view of MSSQL injection attack,the research here thinks that only the active defense can become passive to be active,and then fundamentally lets SQL server achieve a real sense of security.This paper designed and developed a set of active defense software,which realizes active defense by hooking the APIs of SQL Server process through remote thread injection technology.After the active defense software intercepts the creation of process by SQL Server,it sends the process creation parameters to the honey pot for execution,and replaces the result of SQL Server with the reply of the honey pot.With third-party computer monitoring software,monitoring the honey pot,the system can gather the information of the attackers,and track them.The software also features port mapping.Port of the real host can be mapped to the honey pot,thereby to enhance the honey pot deceptive.When malicious attack is detected,the system provides two ways,SMS alert and E-mail alert,to inform your system administrator as soon as possible.