Preventing SQL Injection Attacks Using AMNESIA

Source: Association for Computing Machinery

Favorite

Free registration required

AMNESIA is a tool that detects and prevents SQL injection attacks by combining static analysis and run-time monitoring. Empirical evaluation has shown that AMNESIA is both effective and efficient against SQL injection. Companies and organizations use Web applications to provide a broad range of services to users, such as on-line banking and shopping. Because the databases underlying Web applications often contain confidential information (e.g., customer and financial records), these applications are a frequent target for attacks. One particular type of attack, SQL injection, can give attackers a way to gain access to the databases underlying Web applications and, with that, the power to leak, modify, or even delete information that is stored on these databases.
Format:PDF Size:207.80
Date:May 2006
People who downloaded this item also downloaded