A Countermeasure to SQL Injection Attack for Cloud Environment

作者:Wu, Tsu-Yang*; Chen, Chien-Ming; Sun, Xiuyang; Liu, Shuai; Lin, Jerry Chun-Wei
来源:Wireless Personal Communications, 2017, 96(4): 5279-5293.
DOI:10.1007/s11277-016-3741-7

摘要

Although cloud computing becomes a new computing model, a variety of security threats have been described. Among these threats, SQL injection attack (SQLIA) has received increasing attention recently. In the past, many researchers had proposed several methods to counter SQLIAs. However, these countermeasures of SQLIAs cannot be applied to cloud environments directly. In this paper, we propose a mechanism called CCSD (Cloud Computing SQLIA Detection) to detect SQLIAs. CCSD does not require any access to the application's source code. Hence, it can be directly applied to existing cloud environments. The experimental results demonstrate that CCSD has high accuracy, low false positive rates and low time consumption.

  • 出版日期2017-10
  • 单位哈尔滨工业大学深圳研究生院