Title: A Framework for SQL Injection Investigations.. Detection, Investigation, and Forensics
Authors: Kao, Da-Yu
Lai, Chung-Jui
Su, Ching-Wei
科技管理研究所
Institute of Management of Technology
Keywords: SQL Injection;Cybercrime Investigation;Digital Forensics
Issue Date: 1-Jan-2018
Abstract: Web applications provide information for various private organizations and public sectors. The flaws in web-based application and database can also be utilized for malicious SQL statements. Aggressors often exploit SQL injection (SQLi) flaws during an input validation of web applications to infect database servers and launch cyber-attacks. SQLi attacks derive from the execution of an untrusted input and make the program execute unintended codes with administrative privileges. Website administrators should mitigate SQLi vulnerabilities and LEAs should find a better way to collect relevant evidence. This paper proposes a framework of SQLi Investigation Architecture (SIA) and proves its feasibility in fighting against of SQLi attacks. An effective and efficient approach is also proposed to prosecute SQLi aggressors and keep them away from abusing the database.
URI: http://dx.doi.org/10.1109/SMC.2018.00483
http://hdl.handle.net/11536/151110
ISSN: 1062-922X
DOI: 10.1109/SMC.2018.00483
Journal: 2018 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC)
Begin Page: 2838
End Page: 2843
Appears in Collections:Conferences Paper