Research on the technology of detecting the SQL injection attack and non-intrusive prevention in WEB system

Haibin Hu
DOI: https://doi.org/10.1063/1.4982570
2017-01-01
AIP Conference Proceedings
Abstract:Among numerous WEB security issues, SQL injection is the most notable and dangerous. In this study, characteristics and procedures of SQL injection are analyzed, and the method for detecting the SQL injection attack is illustrated. The defense resistance and remedy model of SQL injection attack is established from the perspective of non-intrusive SQL injection attack and defense. Moreover, the ability of resisting the SQL injection attack of the server has been comprehensively improved through the security strategies on operation system, IIS and database, etc.. Corresponding codes are realized. The method is well applied in the actual projects.
What problem does this paper attempt to address?