J4 ›› 2013, Vol. 35 ›› Issue (2): 68-73.
• 论文 • Previous Articles Next Articles
QIN Guangzan,GUO Fan,XU Fang,YU Min
Received:
Revised:
Online:
Published:
Abstract:
This paper proposes a detection method of SQL injection attack based on static analysis. It statically analyzes the source pages of Web application, extracts taint to execution parameters’ constructed path and forms detection rules. The input parameters in rules are replaced by user input values during dynamic enforcement. By comparing the resulting SQL statements with the original SQL statements in the semantic and structural similarities and discrepancies, the method will determine whether SQL injection attack exists in the Web application. Experiments results show its effectiveness and feasibility since it has little effect on system performance after increasing the filtering module.
Key words: SQL injection;static analysis;construct path;detection rule;Web application
QIN Guangzan,GUO Fan,XU Fang,YU Min. A static analysis method of antiSQL injection attack[J]. J4, 2013, 35(2): 68-73.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2013/V35/I2/68