메뉴 건너뛰기




Volumn , Issue , 2011, Pages 468-471

A survey on SQL injection: Vulnerabilities, attacks, and prevention techniques

Author keywords

[No Author keywords available]

Indexed keywords

SQL INJECTION;

EID: 80052411765     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/ISCE.2011.5973873     Document Type: Conference Paper
Times cited : (73)

References (24)
  • 1
    • 80052414596 scopus 로고    scopus 로고
    • retrieve on 13/01
    • http://www.owasp.org/index.php/Top-10-2010-A1-Injection, retrieve on 13/01/2010
    • (2010)
  • 2
    • 52449092059 scopus 로고    scopus 로고
    • SQL-IDS: A Specification-based Approach for SQLinjection Detection
    • Fortaleza, Ceará, Brazil, ACM
    • K. Kemalis, and T. Tzouramanis (2008). SQL-IDS: A Specification-based Approach for SQLinjection Detection. SAC'08. Fortaleza, Ceará, Brazil, ACM: pp. 2153 2158.
    • (2008) SAC'08 , pp. 2153-2158
    • Kemalis, K.1    Tzouramanis, T.2
  • 3
    • 37349043549 scopus 로고    scopus 로고
    • A Static Analysis Framework for Detecting SQL Injection Vulnerabilities
    • 24-27 July
    • X. Fu, X. Lu, B. Peltsverger, S. Chen, K. Qian, and L. Tao. A Static Analysis Framework for Detecting SQL Injection Vulnerabilities, COMPSAC 2007, pp.87-96, 24-27 July 2007
    • (2007) COMPSAC 2007 , pp. 87-96
    • Fu, X.1    Lu, X.2    Peltsverger, B.3    Chen, S.4    Qian, K.5    Tao, L.6
  • 4
    • 57849137358 scopus 로고    scopus 로고
    • On automated prepared statement generation to remove SQL injection vulnerabilities
    • S. Thomas, L. Williams, and T. Xie, On automated prepared statement generation to remove SQL injection vulnerabilities. Information and Software Technology 51, 589-598 (2009).
    • (2009) Information and Software Technology , vol.51 , pp. 589-598
    • Thomas, S.1    Williams, L.2    Xie, T.3
  • 7
    • 70449097813 scopus 로고    scopus 로고
    • A database security testing scheme of web application
    • 25-28 July
    • Y. Haixia, N. Zhihong, "A database security testing scheme of web application," Proc. of ICCSE '09 , pp. 953-955, 25-28 July 2009.
    • (2009) Proc. of ICCSE '09 , pp. 953-955
    • Haixia, Y.1    Zhihong, N.2
  • 10
    • 77958556162 scopus 로고    scopus 로고
    • SQL injection detection and prevention tools assessment
    • no., 9-11 July
    • A. Tajpour; M. Masrom; M. Z. Heydari.; S. Ibrahim; "SQL injection detection and prevention tools assessment," Proc. Of ICCSIT 2010, vol.9, no., pp.518-522, 9-11 July 2010
    • (2010) Proc. Of ICCSIT 2010 , vol.9 , pp. 518-522
    • Tajpour, A.1    Masrom, M.2    Heydari, M.Z.3    Ibrahim, S.4
  • 11
    • 78649806181 scopus 로고    scopus 로고
    • Evaluation of SQL Injection Detection and Prevention Techniques
    • 28-30 July
    • A. Tajpour; M. JorJor Zade Shooshtari , "Evaluation of SQL Injection Detection and Prevention Techniques," Proc. of CICSyN, 2010, pp.216-221, 28-30 July 2010
    • (2010) Proc. of CICSyN, 2010 , pp. 216-221
    • Tajpour, A.1    JorJor Zade Shooshtari, M.2
  • 12
    • 77951455398 scopus 로고    scopus 로고
    • Looking at Web Security Vulnerabilities from the Programming Language Perspective: A Field Study
    • N. Seixas; J. Fonseca; M. Vieira; H. Madeira, "Looking at Web Security Vulnerabilities from the Programming Language Perspective: A Field Study," Proc. of ISSRE '09, pp.129-135.
    • Proc. of ISSRE '09 , pp. 129-135
    • Seixas, N.1    Fonseca, J.2    Vieira, M.3    Madeira, H.4
  • 18
    • 77949464016 scopus 로고    scopus 로고
    • CANDID: Dynamic Candidate Evaluations for Automatic Prevention of SQL Injection Attacks
    • P. Bisht, P. Madhusudan, and V. N. Venkatakrishnan. CANDID: Dynamic Candidate Evaluations for Automatic Prevention of SQL Injection Attacks. ACM Trans. Inf. Syst. Secur., 13(2):1-39, 2010.
    • (2010) ACM Trans. Inf. Syst. Secur. , vol.13 , Issue.2 , pp. 1-39
    • Bisht, P.1    Madhusudan, P.2    Venkatakrishnan, V.N.3
  • 20
    • 79957814266 scopus 로고    scopus 로고
    • SQLIPA: An Authentication Mechanism Against SQL Injection
    • ISSN 1450-216X
    • S. Ali, SK. Shahzad and H. Javed, "SQLIPA: An Authentication Mechanism Against SQL Injection," European Journal of Scientific Research ISSN 1450-216X Vol.38 No.4 (2009), pp 604-611.
    • (2009) European Journal of Scientific Research , vol.38 , Issue.4 , pp. 604-611
    • Ali, S.1    Shahzad, S.K.2    Javed, H.3
  • 22
    • 50249084452 scopus 로고    scopus 로고
    • DIWeDa - Detecting Intrusions in Web Databases
    • Atluri, V. (ed.) DAS 2008. Springer, Heidelberg
    • A. Roichman, E. Gudes, "DIWeDa - Detecting Intrusions in Web Databases". In: Atluri, V. (ed.) DAS 2008. LNCS, vol. 5094, pp. 313-329. Springer, Heidelberg (2008).
    • (2008) LNCS , vol.5094 , pp. 313-329
    • Roichman, A.1    Gudes, E.2
  • 23
    • 77951105286 scopus 로고    scopus 로고
    • An Approach for SQL Injection Vulnerability Detection
    • 27-29 April
    • Mei Junjin, "An Approach for SQL Injection Vulnerability Detection," Proc. of ITNG '09, pp.1411-1414, 27-29 April 2009.
    • (2009) Proc. of ITNG '09 , pp. 1411-1414
    • Junjin, M.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.