Defending SQL injection attacks based-on intention-oriented detection
Mao Chenyu, Fan Guo · 2016
SQL injection attacks(SQLIA) are the most serious threats to WEB program security, while dynamic analysis may effectively defend SQLIA. An intention-oriented detection approach is proposed to represent all the database operations expected by WEB programmers. It intercepts the requests before user submission and drops the unintentional ones. A language named SQLIDL is proposed to express the user intention of database operations and is used to transform SQL requests into string sets formalized by the deterministic finite automaton (DFA). SQLIDL currently implements the regular expression representation of table names, column names, values and store procedure names. The prototype implementation is evaluated on SecuriBench and the results demonstrate all existing SQL attack patterns can be correctly detected with acceptable run-time overhead.