RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    SQL Query and Attribute Values Scrutiny Method for Detection and Prevention of SQL Injection Attacks : SQL 인젝션 공격의 탐지와 방지를 위한 SQL 쿼리와 속성값 검증 방법

    한글로보기

    https://www.riss.kr/link?id=T14915770

    • 저자
    • 발행사항

      대구 : 경북대학교 대학원, 2018

    • 학위논문사항

      Thesis (M.A.) -- 경북대학교 대학원 , 컴퓨터학부 , 2018. 8

    • 발행연도

      2018

    • 작성언어

      영어

    • 주제어
    • DDC

      005.8 판사항(23)

    • 발행국(도시)

      대한민국

    • 형태사항

      v, 57 p. ; 26 cm.

    • 일반주기명

      Thesis Advisor: 이우진.
      Includes bibliographical references.

    • UCI식별코드

      I804:22001-000000093187

    • 소장기관
      • 경북대학교 중앙도서관 소장기관정보
      • 국립중앙도서관 국립중앙도서관 우편복사 서비스
    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Their nature of ubiquity and adoption of the web as a means of retrieving information and making other financial transactions like e-shopping and e-banking have made the use of web application services most popular. As the use of web application grows, also the number and sophistication of attacks increase. Amongst threats to web applications, SQL Injection attacks have been researched and reported as being top major threats. Attackers inject malicious code or queries to the web application that makes them extract confidential information or sometimes to destruct the database system.
    In this thesis, a both combined static and dynamic analysis effective and simple technique is proposed to detect and prevent SQL injection attacks by splitting both static and dynamic queries into substrings and compare the number of substrings in both queries. Also in queries where splitting techniques do not work, the attribute values in both fixed and runtime query counted and analyzed then the number of attribute values are compared. A technique is simple and effective in a way that it does not employ complex algorithms and operations like parse tree algorithms, DBMS proxy, and libraries. The evaluation results for the proposed technique shows success in detecting and preventing SQL injection attacks and reduces the false positives and false negatives. And this takes place before a SQL query is sent to the back-end database layer.
    번역하기

    Their nature of ubiquity and adoption of the web as a means of retrieving information and making other financial transactions like e-shopping and e-banking have made the use of web application services most popular. As the use of web application grows...

    Their nature of ubiquity and adoption of the web as a means of retrieving information and making other financial transactions like e-shopping and e-banking have made the use of web application services most popular. As the use of web application grows, also the number and sophistication of attacks increase. Amongst threats to web applications, SQL Injection attacks have been researched and reported as being top major threats. Attackers inject malicious code or queries to the web application that makes them extract confidential information or sometimes to destruct the database system.
    In this thesis, a both combined static and dynamic analysis effective and simple technique is proposed to detect and prevent SQL injection attacks by splitting both static and dynamic queries into substrings and compare the number of substrings in both queries. Also in queries where splitting techniques do not work, the attribute values in both fixed and runtime query counted and analyzed then the number of attribute values are compared. A technique is simple and effective in a way that it does not employ complex algorithms and operations like parse tree algorithms, DBMS proxy, and libraries. The evaluation results for the proposed technique shows success in detecting and preventing SQL injection attacks and reduces the false positives and false negatives. And this takes place before a SQL query is sent to the back-end database layer.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    웹 어플리케이션은 정보 검색 및 획득을 위한 수단으로서의 접근 용이성과 인터넷 쇼핑 및 인터넷 뱅킹을 비롯한 금전적 거래 서비스의 확산으로 대중적으로 사용되고 있다. 이와 함께 웹 어플리케이션에 대한 복잡도 높은 공격이 이루어지고 있을 뿐만 아니라 공격의 횟수도 증가하고 있다. 이러한 웹 어플리케이션에 대한 공격 및 위협 중에서도, SQL 인젝션 공격은 가장 보편적인 공격으로 알려졌으며 이에 대한 다양한 연구가 이루어졌다. SQL 인젝션을 사용하는 공격자들은 유해한 코드나 질의을 웹 어플리케이션에 주입하여 기밀 정보를 유출시키거나 데이터베이스를 파괴한다.
    본 논문에서는 정적 및 동적 분석 기술을 조합하여SQL 인젝션 공격을 효과적이고 간단하게 탐지 및 예방하는 기술을 제안한다. 제안한 기술은 정적 질의문과 동적 질의문을 부분문자열로 분할하여 부분문자열의 개수를 비교한다. 분할 기술이 효과가 없는 질의문에 대해서는, 질의문의 속성값을 분석하여 속성값의 개수를 비교한다. 본 기술은 파스 트리 알고리즘, DBMS 프록시, 라이브러리와 같은 복잡한 알고리즘 및 동작을 수반하지 않으므로 효과적이고 간단하다. 본 기술이 탐지 오류를 줄이면서도 SQL 인젝션 공격을 탐지 및 예방할 수 있을 뿐만 아니라, SQL 질의문이 백엔드 데이터베이스 계층에 전달되기 전에 작동할 수 있음을 결과 분석 및 평가에서 보인다.
    번역하기

    웹 어플리케이션은 정보 검색 및 획득을 위한 수단으로서의 접근 용이성과 인터넷 쇼핑 및 인터넷 뱅킹을 비롯한 금전적 거래 서비스의 확산으로 대중적으로 사용되고 있다. 이와 함께 웹 ...

    웹 어플리케이션은 정보 검색 및 획득을 위한 수단으로서의 접근 용이성과 인터넷 쇼핑 및 인터넷 뱅킹을 비롯한 금전적 거래 서비스의 확산으로 대중적으로 사용되고 있다. 이와 함께 웹 어플리케이션에 대한 복잡도 높은 공격이 이루어지고 있을 뿐만 아니라 공격의 횟수도 증가하고 있다. 이러한 웹 어플리케이션에 대한 공격 및 위협 중에서도, SQL 인젝션 공격은 가장 보편적인 공격으로 알려졌으며 이에 대한 다양한 연구가 이루어졌다. SQL 인젝션을 사용하는 공격자들은 유해한 코드나 질의을 웹 어플리케이션에 주입하여 기밀 정보를 유출시키거나 데이터베이스를 파괴한다.
    본 논문에서는 정적 및 동적 분석 기술을 조합하여SQL 인젝션 공격을 효과적이고 간단하게 탐지 및 예방하는 기술을 제안한다. 제안한 기술은 정적 질의문과 동적 질의문을 부분문자열로 분할하여 부분문자열의 개수를 비교한다. 분할 기술이 효과가 없는 질의문에 대해서는, 질의문의 속성값을 분석하여 속성값의 개수를 비교한다. 본 기술은 파스 트리 알고리즘, DBMS 프록시, 라이브러리와 같은 복잡한 알고리즘 및 동작을 수반하지 않으므로 효과적이고 간단하다. 본 기술이 탐지 오류를 줄이면서도 SQL 인젝션 공격을 탐지 및 예방할 수 있을 뿐만 아니라, SQL 질의문이 백엔드 데이터베이스 계층에 전달되기 전에 작동할 수 있음을 결과 분석 및 평가에서 보인다.

    더보기

    목차 (Table of Contents)

    • Abstract ...................................................................................................................... i
    • List of Figures .......................................................................................................... iii
    • List of Tables ............................................................................................................ iv
    • List of Abbreviations ................................................................................................. v
    • Chapter 1. Introduction ....................................................................................... 1
    • Abstract ...................................................................................................................... i
    • List of Figures .......................................................................................................... iii
    • List of Tables ............................................................................................................ iv
    • List of Abbreviations ................................................................................................. v
    • Chapter 1. Introduction ....................................................................................... 1
    • Chapter 2. Background and Related Works ........................................................ 5
    • 2.1 Background ............................................................................................... 5
    • 2.1.1 Web application ................................................................................. 5
    • 2.1.2 Web application architecture ............................................................. 6
    • 2.1.3 SQL Injection .................................................................................... 7
    • 2.1.4 Injection Mechanism ....................................................................... 11
    • 2.1.5 Injection Types ................................................................................ 14
    • 2.2 Related Works ......................................................................................... 18
    • 2.2.1 AMNESIA ....................................................................................... 18
    • 2.2.2 SQLIA Detection by Removal of Query Attribute Values.............. 20
    • 2.2.3 A hybrid method for detection and prevention of SQLIA............... 21
    • 2.2.4 SQLIA Prevention Method based on ISR ....................................... 22
    • Chapter 3. SQL Query and Attribute Values Scrutiny Method ........................ 24
    • 3.1 SQL Query Split ...................................................................................... 29
    • 3.2 SQL Query attributes count ..................................................................... 32
    • 3.3 SQL Query attribute values analysis ....................................................... 35
    • Chapter 4. Implementation and Evaluation ....................................................... 38
    • 4.1 Implementation ........................................................................................ 38
    • 4.2 Evaluation................................................................................................ 40
    • Chapter 5. Conclusion and Future Work .......................................................... 50
    • References ............................................................................................................... 52
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼