Proposed Method for SQL Injection Detection and its Prevention

  • Kumar A
  • Binu S
N/ACitations
Citations of this article
19Readers
Mendeley users who have this article in their library.

Abstract

SQL injection attack is a commonly used method to attack the database server. Injection attacks enable the attacker to bypass the validation and authorization mechanisms used by database server and gain access to the database. The easiest way to launch this attack is by exploiting the loopholes in the validation of user inputs provided through login pages. Each login page that a user visits can contribute towards revealing the identity of the user. Feedbacks given by the server while executing an SQL code can reveal information regarding the vulnerabilities in the validation process of the database server. This information can be misused by the attacker to launch an SQL injection attack. This paper discusses a technique for identifying and preventing SQL injection attack using tokenization concept. The paper discusses a function which verifies the user queries for the presence of various predefined tokens and thereby preventing the access to web pages in cases where the user query includes any of the defined tokens.

Cite

CITATION STYLE

APA

Kumar, A., & Binu, S. (2018). Proposed Method for SQL Injection Detection and its Prevention. International Journal of Engineering & Technology, 7(2.6), 213. https://doi.org/10.14419/ijet.v7i2.6.10569

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free