Analysis of SQL Injection Attack Detection and Prevention on MySQL Database Using Input Categorization and Input Verifier


연구 분야: Databases



학회: 2022 IEEE 8th Information Technology International Seminar (ITIS)


초록

Data leakage affects confidentiality and integrity, which can harm various parties. According to OWASP (Open Web Application Security Project) research, SQL injection attacks rank first in the top web application vulnerabilities. Moreover, the website is directly connected. SQL injection attacks are common on MySQL databases because they are generally more popular than other database systems. One of the efforts to detect and prevent SQL injection attacks is to use input categorization techniques and input verifiers based on input. Application development using SDLC Waterfall. The analysis is obtained from the test results using sqlmap and manually. This paper provides an overview of detection and prevention efforts with input categorization approaches and input verifiers based on the type of SQL injection attack. All applications without prevention and detection can be attacked, while applications with prevention and detection cannot be attacked. This paper designs and develops a web application with and without SQL injection attack detection and prevention using input categorization and input verifier. The results obtained, input categorization, and input verification techniques can detect and prevent SQL injection attacks based on their type, including union-based SQL injection, error-based SQL injection, and blind SQL injection. Input categorization and input verifier can be used in addition to the use of an encrypted database.


Author Profile
Alya Aiman Salsabila Arif

Crypto Software Engineering Politeknik Siber dan Sandi Negara Bogor Indonesia

Indonesia
Author Profile
Rahmat Purwoko

Cryptographic Hardware Engineering Politeknik Siber dan Sandi Negara Bogor Indonesia

Indonesia
Author Profile
Nurul Qomariasih

Crypto Software Engineering Politeknik Siber dan Sandi Negara Bogor Indonesia

Indonesia

📄 논문 정보

발행 연도 2022년
인용수 4
출판 국가 Indonesia
사이트 IEEE
좋아요 수 0

연관 논문 목록 (364건)