Please use this identifier to cite or link to this item: http://localhost:8081/xmlui/handle/123456789/2216
Full metadata record
DC FieldValueLanguage
dc.contributor.authorManikanta, Y. V. N.-
dc.date.accessioned2014-09-27T05:05:37Z-
dc.date.available2014-09-27T05:05:37Z-
dc.date.issued2012-
dc.identifierM.Techen_US
dc.identifier.urihttp://hdl.handle.net/123456789/2216-
dc.guideSardana, Anjali-
dc.description.abstractSQL Injection attacks are the costly and critical attacks on web applications: it is a code injection technique that allows attackers to obtain unrestricted access to the databases and to the potentially sensitive information like usernames, passwords, email ids, credit card details of these databases contain. Various techniques have been proposed to address the problem of SQL Injection attack such as defense coding practices, detection and prevention techniques, and ._ 'intrusion detection systems. However most of these techniques have one or more disadvantages such as requires code modification, applicable to some type of web applications, and address only some attack types.. In this dissertation entitled "Database Level Ids for Detecting and Preventing SQL Injection Attacks", a secure mechanism for protecting web applications from SQL Injection attacks by using framework and database firewall is proposed and implemented. This mechanism uses combined static and dynamic analysis technique. In static analysis, we list all the URLs, forms, injection points, and vulnerable parameters of web application. Thus, we identify valid queries that could be generated by the application. In dynamic analysis, we use database firewall to monitor runtime generated queries and check them against the whitelist of queries. The results show that implemented mechanism is capable of detecting all types of SQL Injection attacks .: without requiring any code modification to the existing web application but with an additional element of deploying a proxy.en_US
dc.language.isoenen_US
dc.subjectSQLen_US
dc.subjectDATABASEen_US
dc.subjectWEB APPLICATIONen_US
dc.subjectELECTRONICS AND COMPUTER ENGINEERINGen_US
dc.titleDATABASE LEVEL IDS FOR DETECTING AND PREVENTING SQL INJECTION ATTACKSen_US
dc.typeM.Tech Dessertationen_US
dc.accession.numberG21980en_US
Appears in Collections:MASTERS' THESES (E & C)

Files in This Item:
File Description SizeFormat 
ECDG21980.pdf3.97 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.