文章詳目資料

Journal of Computers EIMEDLINEScopus

  • 加入收藏
  • 下載文章
篇名 Anti-malicious Injection Based on Meta-programs
卷期 19:1
作者 Lin, Jin-cherngChen, Jan-min
頁次 013-021
關鍵字 Black box testingMalicious injectionInput validationSecurity gatewayEIMEDLINEScopus
出刊日期 200804

中文摘要

英文摘要

Injection attack is a technique to bypass or modify the originally intended functionality of the program by injecting codes into a computer program or system. It is popular in system hacking or cracking to gain information, Privilege escalation or unauthorized access to a system. Many application’s security vulnerabilities result from generic injection problems. Examples of such vulnerabilities are SQL injection, Shell injection and Script injection (Cross Site Scripting). Some applications attempt to protect themselves by filtering malicious input data, but it may not be viable to modify the source of such components (either because the code was shipped in binary form or because the license agreement is prohibitive). We have tried to develop a defense mechanism that can automatically generate meta-programs on security gateway to filter malicious injection. The security gateway is allocated in front of application server to eliminate malicious injection vulnerabilities. To verify the efficiency of the mechanism, we create the web sites made up of some Web applications that often contain third-party vulnerable components shipped in binary form. According to the result of these experiments, our defense mechanism has proved itself efficiency.

相關文獻