Article,

WEEIDS: Web Eccentricity Embezzle Intrusion Detection System for SQLIA

, and .
Imperial Journal of Interdisciplinary Research, (2017)

Abstract

SQL Injection Attack (SQLIA) refers to an injection attack wherein an attacker can execute malicious SQL statements that control a web application’s database server. By leveraging SQL Injection vulnerability, given the right circumstances, an attacker can use it to bypass a web application’s authentication and authorization mechanisms and retrieve the contents of an entire database. SQL Injection can also be used to add, modify and delete records in a database, affecting data integrity. The main idea of our work is to allow developers the freedom to write and execute code without having to worry about these attacks. In this paper we propose a Web Eccentricity Embezzle Intrusion Detection system (WEEIDS) to extract a SQL query connecting to database from a PHP file. The structure of the query under observation will be converted to XML file and compared against the legitimate queries stored in the XML file using association rule mining thus minimizing attacks. WEEIDS is expected to reduce the time and manual effort as it only focuses on fragments that are vulnerable for attacks .

Tags

Users

  • @ijirjournal

Comments and Reviews