首页> 外文会议>International Conference on Cloud Computing and Security >A Mutation Approach of Detecting SQL Injection Vulnerabilities
【24h】

A Mutation Approach of Detecting SQL Injection Vulnerabilities

机译:一种检测SQL注入漏洞的变异方法

获取原文

摘要

As Internet is increasingly prosperous, Web services become more common in our social life. As users can access pages on the Web directly, Web application plays a vital role in various domains such as e-finance and public-services. Inevitably, it will be followed by unprecedented amount of attacks and exploitations. Amongst all of those attacks, SQL injection attacks have consistently high rank in last years due to corresponding vulnerabilities. It is crucial to checking this vulnerabilities before web services being public. In our paper we present an effective approach for testing, MOSA, and mutation operators set to its underpinning. Using this approach we can produce test inputs that cause executable and malignant SQL statement efficiently. Besides that, we do numerous experiments and the results demonstrate that the mutation approach can detect SQL injection vulnerabilities and generate inputs that bypass web application firewalls.
机译:随着Internet的日益繁荣,Web服务在我们的社交生活中变得越来越普遍。由于用户可以直接访问Web页面,因此Web应用程序在电子金融和公共服务等各个领域中起着至关重要的作用。不可避免的是,随之而来的是前所未有的攻击和利用。在所有这些攻击中,由于存在相应的漏洞,SQL注入攻击在过去几年中一直处于较高的排名。在Web服务公开之前检查此漏洞至关重要。在我们的论文中,我们提出了一种有效的测试方法,MOSA和为其设置基础的变异算子。使用这种方法,我们可以产生测试输入,这些输入有效地导致可执行的和恶性的SQL语句。除此之外,我们进行了许多实验,结果表明,变异方法可以检测SQL注入漏洞并生成绕过Web应用程序防火墙的输入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号