arrow
返回

SQLPsdem: A Proxy-Based Mechanism Towards Detecting, Locating and Preventing Second-Order SQL Injections

delete2024-07-01
delete0
PRE
AI
B
Bing Zhang
R
Rong Ren
刘
刘嘉 (Jia Liu)
M
Mingcai Jiang
任
任家东 (Jiadong Ren) *
J
Jingyue Li
DOI:10.1109/TSE.2024.3400404delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Due to well-hidden and stage-triggered properties of second-order SQL injections in web applications, current approaches are ineffective in addressing them and still report high false negatives and false positives. To reduce false results, we propose a Proxy-based static analysis and dynamic execution mechanism towards detecting, locating and preventing second-order SQL injections (SQLPsdem). The static analysis first locates SQL statements in web applications and identifies all data sources and injection points (e.g., Post, Sessions, Database, File names) that injection attacks can exploit. After that, we reconstruct the SQL statements and use attack engines to jointly generate attacks to cover all the state-of-the-art attack patterns so as to exploit these applications. We then use proxy-based dynamic execution to capture the data transmitted between web applications and their databases. The data are the reconstructed SQL statements with variable values from the attack payloads. If a web application is vulnerable, the data will contain malicious attacks on the database. We match the data with rules formulated by attack patterns to detect first and second-order SQL injection vulnerabilities in web applications, particularly the second-order ones. We use a representative and complete coverage of attack patterns and precise matching rules to reduce false results. By escaping and truncating malicious payloads in the data transmitted from the web application to the database, we can eliminate the possible negative impact of the data on the database. In the evaluation, by generating 52,771 SQL injection attacks using four attack generators, SQLPsdem successfully detects 26 second-order (including 13 newly discovered ones) and 375 first-order SQL injection vulnerabilities in 12 open-source web applications. SQLPsdem can also 100% eliminate the malicious impact of the data with negligible overhead.
Keyword:
SQL injection
Databases
Static analysis
Structured Query Language
Payloads
Syntactics
Servers
Second-order SQL injection
static analysis
dynamic execution
proxy
detection and prevention

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.9K
被引数:
1.1W

机构

Y
Yanshan University
学者数:
1.7W
论文数: 1.1W
被引数: 1.3W
引用论文

引用论文

Baleen Whales
err2001-01-01
err0
PREAI
errJ.L. Bannister
err分享
err收藏
err分享
err收藏
First report of detection of the putative receptor of Bacillus thuringiensis toxin Vip3Aa from black cutworm (Agrotis ipsilon)
err2018-03-01
err0
errOAAI
errGamal H. Osman; Waleed J. Altaf; Ibrahim A.S. Saleh; Raya Soltane; Hussein H. Abulreesh; Ibrahim A. Arif; Ahmed M. Ramadan; Yehia A. Osman
err分享
err收藏
ART4SQLi: The ART of SQL Injection Vulnerability Discovery
err2019-12-01
err23
PREAI
errZhang, Long; Zhang, Donghong; Wang, Chenghong; Zhao, Jing; Zhang, Zhenyu
err分享
err收藏
学者 查看更多内容