loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
7th IEEE International Conference on Computer and Information Technology (CIT 2007)
The Automatic Defense Mechanism for Malicious Injection Attack
Aizu-Wakamatsu City, Fukushima, Japan
October 16-October 19
ISBN: 0-7695-2983-6
Jin-Cherng Lin, Tatung University Taipei 10451, Taiwan
Jan-Min Chen, Tatung University Taipei 10451, Taiwan
Injection attack is a technique to inject codes into a computer program or system by taking advantage of the unchecked assumptions the system makes about its inputs. The purpose of the injected code is typically to bypass or modify the originally intended functionality of the program. It is popular in system hacking or cracking to gain information, Privilege escalation or unauthorized access to a system [13]. Many application's security vulnerabilities result from generic injection problems. Examples of such vulnerabilities are SQL injection, Shell injection and Script injection (Cross Site Scripting). Some applications attempt to protect themselves by filtering malicious input data, but it may not be viable to modify the source of such components (either because the code was shipped in binary form or because the license agreement is prohibitive). We have tried to develop a defense mechanism that can automatically produce a proper input validation function on security gateway to filter malicious injection. The security gateway is allocated in front of application server to eliminate malicious injection vulnerabilities. To verify the efficiency of the tool, we pick the websites made up of some Web applications that often contain third-party vulnerable components shipped in binary form. Among these experiments, our defense mechanism has proved their efficiency to avoid malicious injection attack. Keywords Black box testing, Malicious injection, Input validation, Security gateway.
Citation:
Jin-Cherng Lin, Jan-Min Chen, "The Automatic Defense Mechanism for Malicious Injection Attack," cit, pp.709-714, 7th IEEE International Conference on Computer and Information Technology (CIT 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.