Moving Target Defense in Preventing SQL Injection

Kaiyu Feng, Xiao Gu, Wei Peng, Dequan Yang*

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

4 引用 (Scopus)

摘要

The database stores important information about the user, which make it a core part of the website. Therefore, database injection has become a serious cyber-attack. Traditional database injection defenses are passive defenses, which cannot detect new vulnerability before it is exposed. The Moving Target Defense (MTD) method that emerged in recent years has become a breakthrough to solve this problem. This paper mainly establishes the model to verify the possibility of dynamic defense application in database injection defense. This paper first introduces the related concepts SQLI and MTD, then we build models to compare the attack surface of the traditional static defense model and MTD one. It is concluded that with certain conditions, the dynamic defense model has a smaller attack surface, which indicate stronger defense ability.

源语言英语
主期刊名Artificial Intelligence and Security - 5th International Conference, ICAIS 2019, Proceedings
编辑Xingming Sun, Zhaoqing Pan, Elisa Bertino
出版商Springer Verlag
25-34
页数10
ISBN(印刷版)9783030242671
DOI
出版状态已出版 - 2019
活动5th International Conference on Artificial Intelligence and Security, ICAIS 2019 - New York city, 美国
期限: 26 7月 201928 7月 2019

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
11635 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议5th International Conference on Artificial Intelligence and Security, ICAIS 2019
国家/地区美国
New York city
时期26/07/1928/07/19

指纹

探究 'Moving Target Defense in Preventing SQL Injection' 的科研主题。它们共同构成独一无二的指纹。

引用此