Beta
117916

Efficient Solution for Detection and Prevention of SQL Injection Attacks (Wave system technique)

Article

Last updated: 27 Dec 2024

Subjects

-

Tags

تکنولوجيات المعلومات والاتصالات Information Technology and Communications
علوم الحاسباتComputer Sciences .
نظم المعلومات Information Systems، وما يتفرع منها من قواعد البيانات DBs، مستودعات البيانات DWs، و بحيرات البيانات DLs إلخ.
نظم المعلومات الإدارية MIS، ونظم معلومات الأعمال BIS، نظم دعم القرارDSS

Abstract

Abstract SQL Injection attacks are one of the most common threats on web applications that refer to an attacker who can use vulnerability to bypass authentication for retrieving the contents of an entire database then create, delete, update or drop the whole structure. There are many methods used to repel these attacks but none of these methods have proved to work on detecting and preventing all types of SQL injection attacks which means specific method for a certain particular type. The aim of this research is to present a new method to detect and prevent the largest number of these attacks and test it against the 50 codes written by PHP and HTML languages Analysis and comparison have been carried out between the existing solutions YASCA, RIPS and WAVE, questionnaires were completed by experts such as developers and database administrators and identification of the actual risks behind these threats have all helped in addressing the best method to use in securing websites.

DOI

10.21608/jstc.2017.117916

Keywords

SQL Injection, Attack, Prevention-Detection, vulnerability attack. Threats, SQLIA.

Authors

First Name

Mohamed

Last Name

M. EL HADI

MiddleName

-

Affiliation

Sadat Academy for Management Sciences

Email

mohamed.m.elhadi@gmail.com

City

-

Orcid

-

First Name

Christina

Last Name

Albert

MiddleName

-

Affiliation

Sadat Academy for Management Sciences

Email

-

City

-

Orcid

-

First Name

Mona

Last Name

Medhat

MiddleName

-

Affiliation

Sadat Academy for Management Sciences

Email

-

City

-

Orcid

-

Volume

18

Article Issue

الثامن عشر

Related Issue

17723

Issue Date

2017-03-01

Receive Date

2020-10-09

Publish Date

2017-03-01

Page Start

13

Page End

20

Print ISSN

2356-9697

Online ISSN

2735-4350

Link

https://jstc.journals.ekb.eg/article_117916.html

Detail API

https://jstc.journals.ekb.eg/service?article_code=117916

Order

13

Type

• البحوث والدراسات والمقالات المستوفاة للقواعد العلمیة المتعارف علیها، والتى یجریها أو یشارک فى إجرائها أعضاء هیئة التدریس والباحثون فى الجامعات ومراکز البحوث المصریة والعربیة، وذلک باللغتین العربیة والإنجلیزیة .

Type Code

1,502

Publication Type

Journal

Publication Title

مجلة الجمعية المصرية لنظم المعلومات وتکنولوجيا الحاسبات

Publication Link

https://jstc.journals.ekb.eg/

MainTitle

Efficient Solution for Detection and Prevention of SQL Injection Attacks (Wave system technique)

Details

Type

Article

Created At

23 Jan 2023