摘要
SQL注入是黑客使用的一种攻击方式,该攻击主要通过WEB应用来获取、操纵、伪造或删除WEB应用后端的关系型数据库。论述了SQL注入的原理和方法,研究如何生成一个SQL注入自动探测和评估工具及关键技术,并讨论了一定数量的软件测试方法(包括黑盒测试、恶意注入和行为监控)。
SQL Injection is a hacking method that allows an attacker to access a database server. The attacker is then free to extract, modify, add, delete content from the database. The principle and methods of SQL Injection are discussed. Researches are done on how to build a tool and key technologies to detect and assess SQL Injection. A number of software testing techniques are also discussed including black- box testing, fault injection, and behavior monitoring as well.
出处
《株洲工学院学报》
2006年第4期18-21,共4页
Journal of Zhuzhou Institute of Technology