標題: A Framework for SQL Injection Investigations.. Detection, Investigation, and Forensics
作者: Kao, Da-Yu
Lai, Chung-Jui
Su, Ching-Wei
科技管理研究所
Institute of Management of Technology
關鍵字: SQL Injection;Cybercrime Investigation;Digital Forensics
公開日期: 1-Jan-2018
摘要: Web applications provide information for various private organizations and public sectors. The flaws in web-based application and database can also be utilized for malicious SQL statements. Aggressors often exploit SQL injection (SQLi) flaws during an input validation of web applications to infect database servers and launch cyber-attacks. SQLi attacks derive from the execution of an untrusted input and make the program execute unintended codes with administrative privileges. Website administrators should mitigate SQLi vulnerabilities and LEAs should find a better way to collect relevant evidence. This paper proposes a framework of SQLi Investigation Architecture (SIA) and proves its feasibility in fighting against of SQLi attacks. An effective and efficient approach is also proposed to prosecute SQLi aggressors and keep them away from abusing the database.
URI: http://dx.doi.org/10.1109/SMC.2018.00483
http://hdl.handle.net/11536/151110
ISSN: 1062-922X
DOI: 10.1109/SMC.2018.00483
期刊: 2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC)
起始頁: 2838
結束頁: 2843
Appears in Collections:Conferences Paper