论文标题

SQL注入的入侵检测框架

Intrusion Detection Framework for SQL Injection

论文作者

Ali, Israr, Adil, Syed Hasan, Ebrahim, Mansoor

论文摘要

在这个互联网时代,电子商务和电子商务应用程序将数据库用作其组成部分。这些数据库不论所使用的技术都容易受到SQL注入攻击的影响。这些攻击被认为是非常危险的,并且非常易于用于攻击者和入侵者。在本文中,我们提出了一种新的方法,以使用SQL注入来检测攻击者的入侵。我们提出的解决方案的主要思想是创建从授权用户使用关联规则提交的查询中获取的可信赖用户配置文件。之后,我们将使用混合(异常 +滥用)检测模型,该检测模型将取决于数据挖掘技术来检测偏离正常行为概况的查询。正常的行为配置文件将以XML格式创建。通过这种方式,我们可以最大程度地减少假阳性警报。

In this era of internet, E-Business and e-commerce applications are using Databases as their integral part. These Databases irrespective of the technology used are vulnerable to SQL injection attacks. These Attacks are considered very dangerous as well as very easy to use for attackers and intruders. In this paper, we are proposing a new approach to detect intrusion from attackers by using SQL injection. The main idea of our proposed solution is to create trusted user profiles fetched from the Queries submitted by authorized users by using association rules. After that we will use a hybrid (anomaly + misuse) detection model which will depend on data mining techniques to detect queries that deviates from our normal behavior profile. The normal behavior profile will be created in XML format. In this way we can minimize false positive alarms.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源