DESIGN AND ANALYSIS OF SEPTIC PROTOCOL FOR IDENTIFYING SQL INJECTION ATTACKS
Chekuri Sridivya Naga Durga, V. Sarala · Journal of Emerging Technologies and Innovative Research · 2021
Now a days almost all the enterprises try to store their valuable data using back end storage. These databases often integrated with vulnerable applications, such as front end web pages for performing the tasks, which allow injection attacks to be performed. In order to identify such attacks it is very difficult because the system cannot find the difference between normal query and sql attack in easy way. In order to identify such attacks, we propose SEPTIC, a mechanism for DBMS attack prevention, which can also assist on the identification of the vulnerabilities in the applications. The mechanism was implemented in MySQL and evaluated experimentally with various applications and alternative protection approaches. Our results show no false negatives and no false positives with SEPTIC, on the contrary to other solutions.