Evaluation of SQL injection vulnerability detection tools

0Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

SQL injection vulnerabilities have been predominant on database-driven web applications since almost one decade. Exploiting such vulnerabilities enables attackers to gain unauthorized access to the back-end databases by altering the original SQL statements through manipulating user input. Testing web applications for identifying SQL injection vulnerabilities before deployment is essential to get rid of them. However, checking such vulnerabilities by hand is very tedious, difficult, and time-consuming. Web vulnerability static analysis tools are software tools for automatically identifying the root cause of SQL injection vulnerabilities in web applications source code. In this paper, we test and evaluate three free/open source static analysis tools using eight web applications with numerous known vulnerabilities, primarily for false negative rates. The evaluation results were compared and analysed, and they indicate a need to improve the tools.

Cite

CITATION STYLE

APA

Draib, N. A. M., Sultan, A. B. M., Ghani, A. A. B. A., & Zulzalil, H. (2019). Evaluation of SQL injection vulnerability detection tools. International Journal of Engineering and Advanced Technology, 9(1), 1747–1751. https://doi.org/10.35940/ijeat.A2648.109119

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free