International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 154 - Number 11 |
Year of Publication: 2016 |
Authors: Ammar Alazab, Ansam Khresiat |
10.5120/ijca2016911974 |
Ammar Alazab, Ansam Khresiat . New Strategy for Mitigating of SQL Injection Attack. International Journal of Computer Applications. 154, 11 ( Nov 2016), 1-10. DOI=10.5120/ijca2016911974
SQL injection attack (SQLIA) is a serious threat to web applications. A successful SQLIAs can have serious consequences to the victimized organization that include financial lose, reputation lose, compliance and regulatory breach. Therefore, developing approaches for mitigating SQLIA is paramount important. To this end, we propose an approach based on negative tainting along with SQL keyword analysis for detecting and preventing SQLIA. We have tested our proposed approach on all types of SQLIAs techniques by generating SQL queries containing legitimate SQL commands and SQLIA. We present an analysis and evaluation of the proposed approach to demonstrate its effectiveness in detecting and protecting SQLIA attack.