Publication:
Identification and Mitigation Tool for Sql Injection Attacks(SQLIA)

dc.contributor.authorRankothge, W. H
dc.contributor.authorRandeniya, M
dc.contributor.authorSamaranayaka, V
dc.date.accessioned2022-06-02T11:40:04Z
dc.date.available2022-06-02T11:40:04Z
dc.date.issued2020-11-26
dc.description.abstractStructured Query Language Injection Attack (SQLIA) is a very frequent web security vulnerability. The attacker adds a malicious Structured Query Language (SQL) code to the input field of a web form, so that he can gain access to data or make unauthorized changes to data. A successful malicious SQL injection cause serious consequence to the victimized organization such as financial loss, reputation loss, compliance, and regulatory breaches. There have been several research works on detection and prevention of SQL injection attacks. However, still there is an absence of an advanced single tools for both identification and mitigation of SQL injection attacks. We have proposed an approach to identify and mitigate SQL injection attacks using a single tool and it allows software testers to identify the SQL injection vulnerabilities of their web applications during the testing stages. The proposed approach is based on parameterized queries and user input validation. Our results show that the tool provides 100% accurate and efficient results on identification and mitigation of SQL vulnerabilities.en_US
dc.identifier.citationW. H. Rankothge, M. Randeniya and V. Samaranayaka, "Identification and Mitigation Tool for Sql Injection Attacks (SQLIA)," 2020 IEEE 15th International Conference on Industrial and Information Systems (ICIIS), 2020, pp. 591-595, doi: 10.1109/ICIIS51140.2020.9342703.en_US
dc.identifier.doi10.1109/ICIIS51140.2020.9342703en_US
dc.identifier.issn2164-7011
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/2558
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofseries2020 IEEE 15th International Conference on Industrial and Information Systems (ICIIS);
dc.subjectIdentificationen_US
dc.subjectMitigation Toolen_US
dc.subjectSql Injectionen_US
dc.subjectAttacks (SQLIA)en_US
dc.subjectAttacks (SQLIA)en_US
dc.titleIdentification and Mitigation Tool for Sql Injection Attacks(SQLIA)en_US
dc.typeArticleen_US
dspace.entity.typePublication

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Identification_and_Mitigation_Tool_for_Sql_Injection_Attacks_SQLIA.pdf
Size:
113.17 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: