Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Kao, Da-Yu | en_US |
dc.contributor.author | Lai, Chung-Jui | en_US |
dc.contributor.author | Su, Ching-Wei | en_US |
dc.date.accessioned | 2019-04-02T06:04:36Z | - |
dc.date.available | 2019-04-02T06:04:36Z | - |
dc.date.issued | 2018-01-01 | en_US |
dc.identifier.issn | 1062-922X | en_US |
dc.identifier.uri | http://dx.doi.org/10.1109/SMC.2018.00483 | en_US |
dc.identifier.uri | http://hdl.handle.net/11536/151110 | - |
dc.description.abstract | Web applications provide information for various private organizations and public sectors. The flaws in web-based application and database can also be utilized for malicious SQL statements. Aggressors often exploit SQL injection (SQLi) flaws during an input validation of web applications to infect database servers and launch cyber-attacks. SQLi attacks derive from the execution of an untrusted input and make the program execute unintended codes with administrative privileges. Website administrators should mitigate SQLi vulnerabilities and LEAs should find a better way to collect relevant evidence. This paper proposes a framework of SQLi Investigation Architecture (SIA) and proves its feasibility in fighting against of SQLi attacks. An effective and efficient approach is also proposed to prosecute SQLi aggressors and keep them away from abusing the database. | en_US |
dc.language.iso | en_US | en_US |
dc.subject | SQL Injection | en_US |
dc.subject | Cybercrime Investigation | en_US |
dc.subject | Digital Forensics | en_US |
dc.title | A Framework for SQL Injection Investigations.. Detection, Investigation, and Forensics | en_US |
dc.type | Proceedings Paper | en_US |
dc.identifier.doi | 10.1109/SMC.2018.00483 | en_US |
dc.identifier.journal | 2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC) | en_US |
dc.citation.spage | 2838 | en_US |
dc.citation.epage | 2843 | en_US |
dc.contributor.department | 科技管理研究所 | zh_TW |
dc.contributor.department | Institute of Management of Technology | en_US |
dc.identifier.wosnumber | WOS:000459884802149 | en_US |
dc.citation.woscount | 0 | en_US |
Appears in Collections: | Conferences Paper |