Abstract
The SQL injection attacks (SQLIAs) vulnerability is extremely widespread and poses a serious security threat to web applications with built-in access to databases. The SQLIA adversary intelligently exploits the SQL statement parsing operation by web servers via specially constructed SQL statements that subtly lead to non-explicit executions or modifications of corresponding database tables. In this paper, we present a formal and methodical way of modeling SQLIAs by way of augmented attack trees. This modeling explicitly captures the particular subtle incidents triggered by SQLIA adversaries and corresponding state transitions. To the best of our knowledge, this is the first known attack tree modelling of SQL injection attacks.
| Original language | English |
|---|---|
| Title of host publication | ICIME 2010 - 2010 2nd IEEE International Conference on Information Management and Engineering |
| Pages | 182-186 |
| Number of pages | 5 |
| DOIs | |
| Publication status | Published - 2010 |
| Externally published | Yes |
| Event | IEEE International Conference on Information Management and Engineering 2010 - Chengdu, China Duration: 16 Apr 2010 → 18 Apr 2010 Conference number: 2nd https://ieeexplore.ieee.org/xpl/conhome/5472906/proceeding (Proceedings) |
Publication series
| Name | ICIME 2010 - 2010 2nd IEEE International Conference on Information Management and Engineering |
|---|---|
| Volume | 6 |
Conference
| Conference | IEEE International Conference on Information Management and Engineering 2010 |
|---|---|
| Abbreviated title | ICIME 2010 |
| Country/Territory | China |
| City | Chengdu |
| Period | 16/04/10 → 18/04/10 |
| Internet address |
Keywords
- Augmented attack tree
- Modelling
- SQL injection attack
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver