Dissertation > Excellent graduate degree dissertation topics show

The Reasearch and Application of Real-time Random SQL Injection Detection Methods

Author: HuangXiaoBing
Tutor: PengJian
School: Dalian Jiaotong University
Course: Applied Computer Technology
Keywords: SQL Injection Instruction Set Randomization Network Security
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 108
Quote: 1
Read: Download Dissertation

Abstract


With the extensive application of the Internet, we gradually raise the awareness level of network security. : However, the target of cyber attacks and attack methods also change. Attacks against web applications has become a new focus of Internet security attack and defense, WEB application system in a very serious security problem in all the attacks of the WEB application system, SQL injection. Use of this type of attack, the WEB application database access privileges, hackers can be obtained in the case of no authorization to companies and Internet users can obtain confidential data and information, such as account information, online transaction data, and so on, in which case, will give Internet users and the company has brought huge economic losses and insecurity, and this way, we need for SQL injection attacks to implement comprehensive and effective defense. Research purposes to SQL injection, SQL injection attacks and defense measures to carry out in-depth research. At least more than 80% of the network sites exist SQL injection vulnerabilities, hackers take advantage of the WEB server, database vulnerabilities and configuration constructed illegal SQL statements through the program or script into the server and access to the site administrator permissions and database information, and more even can get the information and resources of the entire site, the SQL inject not only pose a serious hazard to the database information, and even a serious threat to the system and Internet users. This paper describes the research background, current status and related research; then SQL injection attacks technical background and realization of the principle which technical background knowledge of the site and SQL injection attacks means, purpose, type, and injection process ; followed by real-time random SQL injection attack detection method proposed instruction set randomization techniques used to effectively guard against SQL injection method, use this method to create a prototype system. First randomized randomized adding a random number, and Internet users to input data to form a complete SQL statement, and then use the SQL statement processing behind the keyword SQL syntax analysis of the keyword in the SQL statement program analysis. Legal SQL statement, the the derandomized SQL statement passed to the database for processing, but the rules of conduct record. Unauthorized users do not know the key of randomized algorithms, so unauthorized users inject SQL statement parser is illegal. The defense system is located between the the WEB application servers and database for WEB applications and databases are transparent and do not need to modify the original application source code, and do not need to modify the server and database platform, the system can effectively prevent SQL injection attacks occur.

Related Dissertations

  1. Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
  2. SX Provincial Public Security Bureau Network Security Corps Performance Evaluation Index System Design,D631.1
  3. The Research of Insurance Network Marketing of China Insurance Company,F724.6
  4. Research and Implemention of Information Security Encryption System Based on the RSA,TP309.7
  5. The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
  6. Research on Streaming Media Detection Methods Against DoS\DDoS Attack Based on Analysis of Self-similarity,TP393.08
  7. Research and Design of Secure Comunication of NVD on Demand System,TP309
  8. Double defensive methods of SQL injection attacks,TP393.08
  9. QH Software Services Marketing Strategy,F426.672
  10. Based on TCP / IP, no shaft offset Remote Monitoring System Design,TP277
  11. The Research of Security Issues in Cognitive Radio Networks,TN915.08
  12. Zhengzhou, China Unicom office automation network security protection Strategy,TP393.08
  13. Based on the index system of e-government extranet security situation assessment study,TP393.08
  14. Query Tokenization Approach to the Detection and Prevention of SQL Injection Attacks,TP311.13
  15. Research of Attack and Defence Technique of Oracle Database,TP311.13
  16. Chinese online banking Innovative Ways,F832.2
  17. The Occupational secondary schools and campus network planning with the the design,G717
  18. The Design of Campus Network Distributed Intrusion Detection System Based on Snort,TP393.08
  19. Global Security Network Design and Implementation,TP393.08
  20. The Research and Application of Support Vector Machine in Intrusion Detection System,TP393.08
  21. Comprehensive host -based firewalls and intrusion detection security system,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile