Prevention Structured Query Language Injection Using Regular Expression and Escape String

Benfano Soewito, Fergyanto Efendy GUNAWAN, Hirzi, Frumentius · Procedia Computer Science · 2018

Information technology enables for new way of commerce, which is a commerce activities through online media (e-commerce). Security becomes an important issue in online-system, because such system is accessible by anyone through the global network -internet. Security in terms of confidentiality, integrity, and availability becomes goals that must be achieved by any system generally, and commerce system especially, because this kind of system contains many sensitive data like customer data and transaction data. SQL Injection is a vulnerability and threat, with the most occurrence in a web based system. In this research we evaluate and analyze source code against SQL injection, and we use regular expression and escape string to prevent the SQL injection. The results of this study are findings of system vulnerability against SQL injection, which are proven by the ability to get data from database, with SQL injection techniques. System vulnerabilities were analyzed, in order to design and implement the solution for it. The solutions then tested, to validate that it has proven effectively fix the vulnerabilities, and can prevent the exploitation by SQL injection. In the end, the conclusion is that initially the system is vulnerable against SQL injection, but then the solution that being implemented has proven effectively fix the issue.

Read the paper · More papers on PaperTik