首页 | 本学科首页   官方微博 | 高级检索  
     

SQLMVED:基于多变体执行的SQL注入运行时防御系统
引用本文:马博林,张铮,刘浩,邬江兴. SQLMVED:基于多变体执行的SQL注入运行时防御系统[J]. 通信学报, 2021, 0(4): 127-138
作者姓名:马博林  张铮  刘浩  邬江兴
作者单位:信息工程大学;网络通信与安全紫金山实验室
基金项目:国家自然科学基金资助项目(No.61521003);国家重点研发计划基金资助项目(No.2018YFB0804003)。
摘    要:SQL解析过程中利用随机化进行SQL注入攻击(SQLIA)防御的有效性是建立在攻击者不了解当前系统采用的具体随机化方法的基础上,因此,攻击者一旦掌握了当前系统的随机化形式,便能够实施有效的SQLIA.为了解决该问题,基于多变体执行设计出一种SQL注入运行时防御系统,多变体间采用互不相同的随机化方法,攻击者注入的非法SQ...

关 键 词:SQL注入攻击  运行时防御  多变体执行  随机化

SQLMVED:SQL injection runtime prevention system based on multi-variant execution
MA Bolin,ZHANG Zheng,LIU Hao,WU Jiangxing. SQLMVED:SQL injection runtime prevention system based on multi-variant execution[J]. Journal on Communications, 2021, 0(4): 127-138
Authors:MA Bolin  ZHANG Zheng  LIU Hao  WU Jiangxing
Affiliation:(Information Engineering University,Zhengzhou 450001,China;Purple Mountain Laboratories,Nanjing 211100,China)
Abstract:The effectiveness of combining SQL statement parsing with randomization to defend against SQL injection attack(SQLIA)was based on the fact that attackers did not know about the current method of randomization adopted by system.Therefore,once attackers had mastered the current method of randomization who can launch effective SQLIA.In order to solve this problem,a SQL injection runtime prevention system based on multi-variant execution was designed,the multi-variant apply randomization methods from any other,so that illegal SQL statements could not be parsed successfully by all variants.Even if attackers had mastered the method of randomization,illegal SQL statements could only be parsed successfully by a certain variant at most,meanwhile the parsing results of multiple variants were voted to find the abnormality in time and block attack path.The prototype system SQLMVED is implemented for Web services and experiments show that the prototype can effectively defeat SQLIA.
Keywords:SQL injection attack  runtime prevention  multi-variant execution  randomization
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号