Effectiveness of structured query language injection attacks detection mechanisms

Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order...

Full description

Saved in:
Bibliographic Details
Main Author: Mohamad, Nurul Zawiyah
Format: Thesis
Language:English
Published: 2008
Subjects:
Online Access:http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf
http://eprints.utm.my/id/eprint/9510/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:856?site_name=Restricted Repository
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknologi Malaysia
Language: English
id my.utm.9510
record_format eprints
spelling my.utm.95102018-07-19T01:51:07Z http://eprints.utm.my/id/eprint/9510/ Effectiveness of structured query language injection attacks detection mechanisms Mohamad, Nurul Zawiyah QA75 Electronic computers. Computer science Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order to keep sensitive and confidential information. Since SQL injection attacks occurred as a new way of accessing database through the application rather than directly through the database itself, they have become popular among hackers and malicious users. Many prevention and detection mechanisms are developed to handle this problem but these mechanisms have their limitations. In this study, two mechanisms, AMNESIA and SQL Guard are adopted for a practical evaluation to search for the better technique in detecting SQL injection attacks. These techniques will be called Technique A and Technique B respectively and will be evaluated on their effectiveness and efficiency using precision and recall measure against two web applications, Mekar and myMarket. The study will show that Technique B is a better approach on detecting SQL injection attacks. 2008-10 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf Mohamad, Nurul Zawiyah (2008) Effectiveness of structured query language injection attacks detection mechanisms. Masters thesis, Universiti Teknologi Malaysia, Faculty of Computer Science and Information System. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:856?site_name=Restricted Repository
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic QA75 Electronic computers. Computer science
spellingShingle QA75 Electronic computers. Computer science
Mohamad, Nurul Zawiyah
Effectiveness of structured query language injection attacks detection mechanisms
description Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order to keep sensitive and confidential information. Since SQL injection attacks occurred as a new way of accessing database through the application rather than directly through the database itself, they have become popular among hackers and malicious users. Many prevention and detection mechanisms are developed to handle this problem but these mechanisms have their limitations. In this study, two mechanisms, AMNESIA and SQL Guard are adopted for a practical evaluation to search for the better technique in detecting SQL injection attacks. These techniques will be called Technique A and Technique B respectively and will be evaluated on their effectiveness and efficiency using precision and recall measure against two web applications, Mekar and myMarket. The study will show that Technique B is a better approach on detecting SQL injection attacks.
format Thesis
author Mohamad, Nurul Zawiyah
author_facet Mohamad, Nurul Zawiyah
author_sort Mohamad, Nurul Zawiyah
title Effectiveness of structured query language injection attacks detection mechanisms
title_short Effectiveness of structured query language injection attacks detection mechanisms
title_full Effectiveness of structured query language injection attacks detection mechanisms
title_fullStr Effectiveness of structured query language injection attacks detection mechanisms
title_full_unstemmed Effectiveness of structured query language injection attacks detection mechanisms
title_sort effectiveness of structured query language injection attacks detection mechanisms
publishDate 2008
url http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf
http://eprints.utm.my/id/eprint/9510/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:856?site_name=Restricted Repository
_version_ 1643645174046261248