SQL Injection Attack Scanner Using Boyer-Moore String Matching Algorithm

Teh Faradilla Abdul Rahman · Journal of Computers · 2017

In this day and age, the proliferation of fast Internet and advanced technology, have contributed to the development of millions of web applications and the number is going to continue to increase every day.With their various purposes such as business promotions, online shopping, e-learning and social media, it has increased the possibility of privacy violation, information leakage, unauthorized access and some other security aspects.These attacks can be launched by using several methods; one of them is through a Structured Query Language (SQL) injection.Even though there are several approaches that have been introduced to detect SQL injections such as Brute Force and Knuth-Morris-Pratt, there are still some weaknesses encountered.Therefore in this paper, we studied about the SQL injection methodology and detection models for web vulnerabilities.Apart from that, we proposed a detection model to scan SQL injection on the web environment, based on the defined and identified criteria using the Boyer-Moore String Matching Algorithm.From several tests that had been done, the results showed that the proposed model is able to detect vulnerable web applications with the de fined criteria of the SQL Injection.In conclusion, this proposed model can be used by web application developer and system admin to secure the application from being attacked and compromised.

Read the paper · More papers on PaperTik