標題: | A Framework for SQL Injection Investigations.. Detection, Investigation, and Forensics |
作者: | Kao, Da-Yu Lai, Chung-Jui Su, Ching-Wei 科技管理研究所 Institute of Management of Technology |
關鍵字: | SQL Injection;Cybercrime Investigation;Digital Forensics |
公開日期: | 1-一月-2018 |
摘要: | Web applications provide information for various private organizations and public sectors. The flaws in web-based application and database can also be utilized for malicious SQL statements. Aggressors often exploit SQL injection (SQLi) flaws during an input validation of web applications to infect database servers and launch cyber-attacks. SQLi attacks derive from the execution of an untrusted input and make the program execute unintended codes with administrative privileges. Website administrators should mitigate SQLi vulnerabilities and LEAs should find a better way to collect relevant evidence. This paper proposes a framework of SQLi Investigation Architecture (SIA) and proves its feasibility in fighting against of SQLi attacks. An effective and efficient approach is also proposed to prosecute SQLi aggressors and keep them away from abusing the database. |
URI: | http://dx.doi.org/10.1109/SMC.2018.00483 http://hdl.handle.net/11536/151110 |
ISSN: | 1062-922X |
DOI: | 10.1109/SMC.2018.00483 |
期刊: | 2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC) |
起始頁: | 2838 |
結束頁: | 2843 |
顯示於類別: | 會議論文 |