Title: Analysis and implementation of SQL injection attack and countermeasures using SQL injection prevention techniques
Authors: A. Jesudoss; Theresa M. Mercy; A. Christy; M. Maheswari; M. Selvi; V. Ulagamuthalvi
Addresses: Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, Tamil Nadu, India ' Department of Electronics and Communication Engineering, Prince Shri Venkateswara Padmavathy Engineering College, Chennai, Tamil Nadu, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India
Abstract: SQL injection attack is the most critical and very common attack to security of web applications. The paper analyses the vulnerabilities that arise due to SQL injection attacks and presents consolidated prevention techniques which consider all vulnerabilities and identifies the SQL injection attacks. It also provides appropriate solution for safeguarding against SQL injection attacks. While being cost-effective, these prevention techniques are also easy to configure, administer and implement. Experimental results have proven that these prevention techniques efficiently identify and protect against SQL injection attacks. The prevention techniques discussed in this paper have been implemented and tested effectively. The results of testing are satisfactory.
Keywords: SQL injection; malicious input; validation; web application firewall; injection attack.
DOI: 10.1504/IJESMS.2022.126305
International Journal of Engineering Systems Modelling and Simulation, 2022 Vol.13 No.4, pp.262 - 267
Received: 08 Apr 2021
Accepted: 16 Aug 2021
Published online: 19 Oct 2022 *