SQL Injection Detection and Prevention using Aho-Corasick Pattern Matching Algorithm

Shreya Kini, Anushka Parvate Patil, M Pooja, Adithya Balasubramanyam · 2022 3rd International Conference for Emerging Technology (INCET) · 2022

With growth of Internet and World Wide Web, the human dependency on websites and web applications has increased significantly in present days. Browsers and general web concepts are more familiar to most people to use than any other abstract computing interface. Users performing sensitive transactions online have paved a way for the attackers to spoof and tamper the transaction data. SQL Injection is one of the most frequent web attack methods used by attackers to steal confidential data from organisations. It is a code injection technique that allows hackers to inject malicious SQL statements into input fields, which is then executed by the underlying SQL database. Attackers can also use web application URLs for inserting malicious SQL queries. Although a significant amount of research has been done on SQLIA Detection and Prevention, SQL injection attacks are still prevalent and cannot be eliminated completely. In this paper, we have provided an overview of SQL Injection vulnerability, different forms of SQL Injection Attacks and threats posed by the attack. We propose a system to secure web applications using Hashing and Aho-Corasick pattern matching algorithm.

Read the paper · More papers on PaperTik