首页> 外文会议>IEEE International Conference on Cyber Security and Cloud Computing >SQLIIDaaS: A SQL Injection Intrusion Detection Framework as a Service for SaaS Providers
【24h】

SQLIIDaaS: A SQL Injection Intrusion Detection Framework as a Service for SaaS Providers

机译:SQLIIDAAS:SQL注入入侵检测框架作为SaaS提供商的服务

获取原文

摘要

Recently, we are attending to the proliferation of Cloud Computing (CC) as the new trending internet-based-Platform. Thanks to the outsourcing paradigm, CC is enabling many services. Software as a Service (SaaS) is one of those cloud-based-services. Indeed, SaaS model allows providers to reduce the cost of maintenance and management by transferring traditional on premise deployment to public Cloud. Clients can subscribe, in self-service, to SaaS services based on a pay-per-use model. However, since user data are outsourced to the Cloud, serious security breaches are rising and could harm the reputation of providers and slow down the subscription of clients. SQL injection attack (SQLIA) is one of the most critical SaaS vulnerabilities that allows attackers to violate the availability, confidentiality and integrity of user data. In this paper, we propose SQL injection intrusion detection framework as a service for SaaS providers, SQLIIDaaS, which allows a SaaS provider to detect SQLIAs targeting several SaaS applications without reading, analyzing or modifying the source code. To achieve SQL query/HTTP request mapping, we propose an event correlation based on the similarity between literals in SQL queries and parameters in HTTP requests. SQLIIDaaS is integrated and validated in Amazon Web Services (AWS). A SaaS provider can subscribe to this framework and launch its own set of virtual machines, which holds on-demand self-service, resource pooling, rapid elasticity, and measured service properties.
机译:最近,我们正在参加云计算(CC)的扩散,作为基于新的趋势的互联网平台。由于外包范式,CC正在实现许多服务。作为服务(SaaS)的软件是基于云的服务之一。事实上,SaaS模型允许提供商通过将传统的前提部署转移到公共云来降低维护和管理的成本。客户可以根据每次使用付费模型,在自助服务中订阅SaaS服务。但是,由于用户数据被外包给云,因此严重的安全漏洞正在上升,可能会损害提供商的声誉并减慢客户的订阅。 SQL注入攻击(SQLIA)是最关键的SAAS漏洞之一,允许攻击者违反用户数据的可用性,机密性和完整性。在本文中,我们将SQL注入入侵检测框架作为SaaS提供商的服务,SQLIIDAAS的服务,它允许SaaS提供商在不读取,分析或修改源代码的情况下检测若干SaaS应用程序的SQLias。为了实现SQL查询/ HTTP请求映射,我们提出了一种基于SQL查询和HTTP请求中的参数之间的文字的相似性的事件相关性。 SQLIIDAAS在Amazon Web服务(AWS)中集成并验证。 SaaS提供商可以订阅此框架并启动自己的一组虚拟机,该计算机可按需自助服务,资源池,快速弹性和测量服务属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号