Design and Implementation of a Defense Mechanism for SQL Injection Attack

Ye Du,Jiqiang Liu,Jieyuan Li,Cheng Li
DOI: https://doi.org/10.1115/1.802977.paper187
2009-01-01
Abstract:Based on the analysis of several kinds of methods generally used to intercept network packets in different layers, a NDIS intermediate driver-based defense mechanism for SQL injection attack is proposed, and the structure is designed. The system is composed of NDIS-based data package capture module, SQL injection attack detection module and rules base. Characteristics of every entity are discussed in detail. Finally, experiments results show that the system can detect SQL injection attacks and intercept malicious packets effectively.
What problem does this paper attempt to address?