期刊文献+

基于正则表示的SQL注入过滤模块设计 被引量:16

Design of SQL Injection Filtering Module Based on Regular Expression
下载PDF
导出
摘要 研究SQL注入攻击行为及语法特征,采用正则表达式对攻击特征进行描述,在此基础上设计Web服务端SQL注入攻击过滤模块,使Http请求被提交至系统模块处理前实现注入攻击检查。测试结果表明,与单纯基于关键字的过滤相比,基于正则表示的过滤具有更高的识别率和较低的误报率,加载了过滤模块的Web服务器能较好地拦截多种SQL注入攻击,并且服务延迟较小。 This paper researches SQL injection attack and grammatical features,constructs the regular expression for these attacks,and designs a SQL injection attack filter module inside Web server based on the filter rules using regular expression.It makes Http request realize injection attack detection before be submitted to the system module.Test results show that compared with filtering based on pure key-words,the filtering based on regular expression has higher recognition rate and lower false positive rate.Web server loaded with filtering module can defense SQL injection attacks effectively,and service delay is smaller.
出处 《计算机工程》 CAS CSCD 北大核心 2011年第5期158-160,共3页 Computer Engineering
基金 国家自然科学基金资助项目(60873265)
关键词 SQL注入 正则表示 服务端防御 SQL injection regular expression server defense
  • 相关文献

参考文献5

  • 1William G J, Viegas H J, Orso A. A Classification of SQL Injection Attacks and Countermeasures[C]//Proc. of International Symposium on Secure Software Engineering. Arlington, USA: IEEE Press. 2006.
  • 2Su Zhendong, Wassermann G. The Essence of Command Injection Attacks in Web Applications[C]//Proc. of Annual Symposium on Principles of Programming Languages. Charleston, USA: [s. n.], 2006.
  • 3Stuttard D, Pinto M. The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws[M].北京:人民邮电出版社, 2009.
  • 4Friedl J E F, Mastering Regular Expressions[M].北京:电子工业出版社,2009.
  • 5宋友,梁士兴,黄璐.通用文本处理方法的研究与设计[J].计算机工程,2010,36(6):1-4. 被引量:3

二级参考文献4

共引文献2

同被引文献105

引证文献16

二级引证文献43

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部