【24h】

Protecting Database Centric Web Services against SQL/XPath Injection Attacks

机译:保护以数据库为中心的Web服务免受SQL / XPath注入攻击

获取原文

摘要

Web services represent a powerful interface for back-end database systems and are increasingly being used in business critical applications. However, field studies show that a large number of web services are deployed with security flaws (e.g., having SQL Injection vulnerabilities). Although several techniques for the identification of security vulnerabilities have been proposed, developing non-vulnerable web services is still a difficult task. In fact, security-related concerns are hard to apply as they involve adding complexity to already complex code. This paper proposes an approach to secure web services against SQL and XPath Injection attacks, by transparently detecting and aborting service invocations that try to take advantage of potential vulnerabilities. Our mechanism was applied to secure several web services specified by the TPC-App benchmark, showing to be 100% effective in stopping attacks, non-intrusive and very easy to use.
机译:Web服务代表了后端数据库系统的强大接口,并且越来越多地用于关键业务应用程序中。但是,现场研究表明,部署的许多Web服务都存在安全漏洞(例如,具有SQL注入漏洞)。尽管已经提出了几种用于识别安全漏洞的技术,但是开发无漏洞的Web服务仍然是一项艰巨的任务。实际上,与安全相关的担忧很难解决,因为它们涉及到为已经很复杂的代码增加复杂性。本文提出了一种通过透明地检测和中止试图利用潜在漏洞的服务调用来保护Web服务免受SQL和XPath注入攻击的方法。我们的机制用于保护TPC-App基准测试指定的多个Web服务,显示出100%有效地阻止了攻击,非侵入式且易于使用。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号