SQLIA Detection and Prevention Techniques

Mazoon Al Rubaiei, Thuraiya Al Yarubi, Maiya Al Saadi, Basant Kumar · 2020

Structure Query Language Injection (SQLI) is one of the top most threat to web-based applications (Like e-commerce, banking, shopping, trading, blogs, etc.) which are connected to the database. The attacker has the ability to get full access and the full control of the database or the application and that drives to removing, modifying and changing significant data. This can be performed by the attacker when a sequence of malicious SQL statements are injected by the attacker into a query through an input that is not validated. Finding the proper solution to stop or mitigate the SQL injection is necessary due to the importance of security of web applications. Many researchers have studied SQLIA detection and prevention extensively and have proposed various methods. However, these techniques are not enough because usually, they have limitations cannot stop all type of attacks. This paper presents background study about classical types of SQLIA, detection and prevention techniques as well as evaluation of these approaches against those types of attacks.

Read the paper · More papers on PaperTik