Abstract | ||
---|---|---|
With the development of network technology, web services become more convenient and popular. However, web services are also facing serious security threats, especially SQL injection attack(SQLIA). Due to the diversity of attack techniques and the static of defense configurations, it is difficult for existing passive defence methods to effectively defend against all SQLIAs. To reduce the risk of successful SQLIAs and increase the difficulty of the attacker, an effective defence technique based on moving target defence (MTD) called dynamic defence to SQLIA (DTSA) was presented in this article. DTSA diversifies the types of databases and implementation languages dynamically, turns the Web server into an untraceable and unpredictable moving target and slows down SQLIAs. Moreover, the period of mutation was determined by the concept of dynamic programming so as to reduce the hazards caused by SQLIAs and minimize the impact on normal users as much as possible. Final, the experimental results showed that the proposed defence method can effectively defend against injection attacks in relational databases. |
Year | DOI | Venue |
---|---|---|
2019 | 10.1007/978-3-030-38991-8_34 | ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING (ICA3PP 2019), PT I |
Keywords | DocType | Volume |
Moving target defense, SQL injection attack, WEB service, Mutation period, Network security | Conference | 11944 |
ISSN | Citations | PageRank |
0302-9743 | 0 | 0.34 |
References | Authors | |
0 | 5 |
Name | Order | Citations | PageRank |
---|---|---|---|
Huan Zhang | 1 | 0 | 1.01 |
Kangfeng Zheng | 2 | 73 | 20.26 |
Xiaodan Yan | 3 | 12 | 1.92 |
Shoushan Luo | 4 | 35 | 10.89 |
Bin Wu | 5 | 8 | 2.56 |