Back to Search Start Over

A systematic review of detection and prevention techniques of SQL injection attacks.

Authors :
Nasereddin, Mohammed
ALKhamaiseh, Ashaar
Qasaimeh, Malik
Al-Qassas, Raad
Source :
Information Security Journal: A Global Perspective; 2023, Vol. 32 Issue 4, p252-265, 14p
Publication Year :
2023

Abstract

SQL injection is a type of database-targeted attack for data-driven applications. It is performed by inserting malicious code in the SQL query to alter and modify its meaning, enabling the attacker to retrieve sensitive data or to access the database. Many techniques have been improved and proposed to detect and mitigate these types of attacks. This paper provides a systematic review for a pool of 60 papers on web applications' SQL injection detection methods. The pool was selected using a developed searching and filtering methodology for the existing literature based on scholar databases (IEEE, ScienceDirect, and Springer) with the aim to provide specific answering for several research questions in the area of SQL injection detection. This provides a basis for the design and use of effective SQL injection detection methods. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
19393555
Volume :
32
Issue :
4
Database :
Complementary Index
Journal :
Information Security Journal: A Global Perspective
Publication Type :
Academic Journal
Accession number :
164053997
Full Text :
https://doi.org/10.1080/19393555.2021.1995537