首页 | 本学科首页   官方微博 | 高级检索  
     

用于SQL注入检测的语句块摘要树模型
引用本文:黄保华,马岩,谢统义. 用于SQL注入检测的语句块摘要树模型[J]. 信息安全与技术, 2012, 3(3): 34-37
作者姓名:黄保华  马岩  谢统义
作者单位:广西大学计算机与电子信息学院,广西南宁,530004
基金项目:国家自然科学基金(N0.10876012);南宁市科学研究与技术开发计划(No.201003064G);广西大学科研基金(No.XBZl00102).
摘    要:SQL注入具有危害性大而实施简单的特点,目前已经成为危害网络信息安全的主要攻击方法之一。本文提出一个用于SQL注入检测的语句块摘要树模型,定义抽象SQL语句、语句块和反映应用系统功能的语句块摘要树,给出该树的生成算法和基于该树的SQL注入检测算法,将检测纳入到应用系统执行的SQL语句序列上下文中,提高了检测的准确性,降低了误报率。实验表明,基于语句块摘要树模型实现SQL注入检测的中间件对系统性能影响很小,说明了模型的有效性和可行性。

关 键 词:SQL注入  抽象SQL语句  语句块摘要树

Statement Block Digest Tree Model for SQL Injection Detection
Huang Bao-hua Ma Yan Xie Tong-yi. Statement Block Digest Tree Model for SQL Injection Detection[J]. Information Security and Technology, 2012, 3(3): 34-37
Authors:Huang Bao-hua Ma Yan Xie Tong-yi
Affiliation:Huang Bao-hua Ma Yan Xie Tong-yi ( College of Computer & Electronics & Information, Guangxi University GuangxiNanning 530004 )
Abstract:For its big harm and easiness of carrying out, SQL Injection is now a main attacking method hurting the network and information security. This paper proposes a statement block digest tree model for SQL injection detection. This model defines abstract SQL statement, SQL statement block and itsdigest tree in accordance with the function of application, and presents algorithms generating the tree and detecting SQL injection based on the tree. By putting detection on the context of executing SQL statement sequence of application, this model increases the veracity and decreases the mistake rate of detection. Experiments show that the SQL injection detection middleware implemented the model only makes little affect on the performance of system, andimply that the model is efficient and feasible.
Keywords:SQL Injection  Abstract SQL Statement  Statement Block Digest Tree
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号