메뉴 건너뛰기




Volumn , Issue , 2006, Pages 175-185

Using positive tainting and syntax-aware evaluation to counter SQL injection attacks

Author keywords

Dynamic tainting; Runtime monitoring; SQL injection

Indexed keywords

DYNAMIC TAINTING; RUNTIME MONITORING; SQL INJECTION;

EID: 34547379435     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1181775.1181797     Document Type: Conference Paper
Times cited : (154)

References (27)
  • 5
    • 34547343191 scopus 로고    scopus 로고
    • T. O. Foundation. Top ten most critical web application vulnerabilities, 2005. http://www.owasp.org/documentation/topten.html.
    • T. O. Foundation. Top ten most critical web application vulnerabilities, 2005. http://www.owasp.org/documentation/topten.html.
  • 11
    • 0010729284 scopus 로고    scopus 로고
    • Microsoft Press, Redmond, Washington, Second Edition
    • M. Howard and D. LeBlanc. Writing Secure Code. Microsoft Press, Redmond, Washington, Second Edition, 2003.
    • (2003) Writing Secure Code
    • Howard, M.1    LeBlanc, D.2
  • 14
    • 33751027156 scopus 로고    scopus 로고
    • N. Jovanovic, C. Kruegel, and E. Kirda. Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In 2006 IEEE Symposium on Security and Privacy, May 2006.
    • N. Jovanovic, C. Kruegel, and E. Kirda. Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In 2006 IEEE Symposium on Security and Privacy, May 2006.
  • 16
    • 33745635923 scopus 로고    scopus 로고
    • SQL Injection Signatures Evasion
    • Apr
    • O. Maor and A. Shulman. SQL Injection Signatures Evasion. White paper, Imperva, Apr. 2004. http://www.imperva.com/application.defense_center/ white_papers/sql_injection_signatures_evasion.html.
    • (2004) White paper, Imperva
    • Maor, O.1    Shulman, A.2
  • 22
  • 26
    • 34547381464 scopus 로고    scopus 로고
    • G. Wassermann and Z. Su. An Analysis Framework for Security in Web Applications. In Proc. of the FSE Workshop on Specification and Verification of Component-Based Systems (SAVCBS 2004), pages 70-78, Oct. 2004.
    • G. Wassermann and Z. Su. An Analysis Framework for Security in Web Applications. In Proc. of the FSE Workshop on Specification and Verification of Component-Based Systems (SAVCBS 2004), pages 70-78, Oct. 2004.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.