Effectiveness of structured query language injection attacks detection mechanisms
Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order...
Saved in:
Main Author: | |
---|---|
Format: | Thesis |
Language: | English |
Published: |
2008
|
Subjects: | |
Online Access: | http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
id |
my-utm-ep.9510 |
---|---|
record_format |
uketd_dc |
spelling |
my-utm-ep.95102018-07-19T01:51:07Z Effectiveness of structured query language injection attacks detection mechanisms 2008-10 Mohamad, Nurul Zawiyah QA75 Electronic computers. Computer science Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order to keep sensitive and confidential information. Since SQL injection attacks occurred as a new way of accessing database through the application rather than directly through the database itself, they have become popular among hackers and malicious users. Many prevention and detection mechanisms are developed to handle this problem but these mechanisms have their limitations. In this study, two mechanisms, AMNESIA and SQL Guard are adopted for a practical evaluation to search for the better technique in detecting SQL injection attacks. These techniques will be called Technique A and Technique B respectively and will be evaluated on their effectiveness and efficiency using precision and recall measure against two web applications, Mekar and myMarket. The study will show that Technique B is a better approach on detecting SQL injection attacks. 2008-10 Thesis http://eprints.utm.my/id/eprint/9510/ http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf application/pdf en public http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:856?site_name=Restricted Repository masters Universiti Teknologi Malaysia, Faculty of Computer Science and Information System Faculty of Computer Science and Information System |
institution |
Universiti Teknologi Malaysia |
collection |
UTM Institutional Repository |
language |
English |
topic |
QA75 Electronic computers Computer science |
spellingShingle |
QA75 Electronic computers Computer science Mohamad, Nurul Zawiyah Effectiveness of structured query language injection attacks detection mechanisms |
description |
Database security is one of the most essential factors in keeping stored information safe. These days, web applications are used widely as a meddler between computer users. Web applications are also used mostly by e-commerce companies, and these types of applications need a secured database in order to keep sensitive and confidential information. Since SQL injection attacks occurred as a new way of accessing database through the application rather than directly through the database itself, they have become popular among hackers and malicious users. Many prevention and detection mechanisms are developed to handle this problem but these mechanisms have their limitations. In this study, two mechanisms, AMNESIA and SQL Guard are adopted for a practical evaluation to search for the better technique in detecting SQL injection attacks. These techniques will be called Technique A and Technique B respectively and will be evaluated on their effectiveness and efficiency using precision and recall measure against two web applications, Mekar and myMarket. The study will show that Technique B is a better approach on detecting SQL injection attacks. |
format |
Thesis |
qualification_level |
Master's degree |
author |
Mohamad, Nurul Zawiyah |
author_facet |
Mohamad, Nurul Zawiyah |
author_sort |
Mohamad, Nurul Zawiyah |
title |
Effectiveness of structured query language injection attacks detection mechanisms |
title_short |
Effectiveness of structured query language injection attacks detection mechanisms |
title_full |
Effectiveness of structured query language injection attacks detection mechanisms |
title_fullStr |
Effectiveness of structured query language injection attacks detection mechanisms |
title_full_unstemmed |
Effectiveness of structured query language injection attacks detection mechanisms |
title_sort |
effectiveness of structured query language injection attacks detection mechanisms |
granting_institution |
Universiti Teknologi Malaysia, Faculty of Computer Science and Information System |
granting_department |
Faculty of Computer Science and Information System |
publishDate |
2008 |
url |
http://eprints.utm.my/id/eprint/9510/1/NurulZawiyahMohamadMFSKSM2008.pdf |
_version_ |
1747814743326851072 |