Skip to main navigation Skip to search Skip to main content

Augmented attack tree modeling of SQL injection attacks

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

The SQL injection attacks (SQLIAs) vulnerability is extremely widespread and poses a serious security threat to web applications with built-in access to databases. The SQLIA adversary intelligently exploits the SQL statement parsing operation by web servers via specially constructed SQL statements that subtly lead to non-explicit executions or modifications of corresponding database tables. In this paper, we present a formal and methodical way of modeling SQLIAs by way of augmented attack trees. This modeling explicitly captures the particular subtle incidents triggered by SQLIA adversaries and corresponding state transitions. To the best of our knowledge, this is the first known attack tree modelling of SQL injection attacks.

Original languageEnglish
Title of host publicationICIME 2010 - 2010 2nd IEEE International Conference on Information Management and Engineering
Pages182-186
Number of pages5
DOIs
Publication statusPublished - 2010
Externally publishedYes
EventIEEE International Conference on Information Management and Engineering 2010 - Chengdu, China
Duration: 16 Apr 201018 Apr 2010
Conference number: 2nd
https://ieeexplore.ieee.org/xpl/conhome/5472906/proceeding (Proceedings)

Publication series

NameICIME 2010 - 2010 2nd IEEE International Conference on Information Management and Engineering
Volume6

Conference

ConferenceIEEE International Conference on Information Management and Engineering 2010
Abbreviated titleICIME 2010
Country/TerritoryChina
CityChengdu
Period16/04/1018/04/10
Internet address

Keywords

  • Augmented attack tree
  • Modelling
  • SQL injection attack

Cite this