摘要
SQL注入攻击是网站常见的安全缺陷。为此,基于隐马尔可夫模型提出一种新的SQL注入检测方法。通过对SQL语句进行分词解析获取特征,结合隐马尔可夫模型和相似度距离算法,从而识别出真正的非法SQL语句。实验表明,该模型对于非法SQL语句的识别是简单有效的。
SQL injection attacks pose a common threat to the security of Web applications. This paper proposed a new technique based on hidden Markov mode for protecting existing Web application against SQL injection.Features of SQL statements can be obtained by word segmentation parsing.We take bothhidden Markov mode and similarity distance methods,and identify the true illegal SQL statements.Experimental results prove that this proposed approach is simple and effectivefor detecting illegal SQL statements.
出处
《信息网络安全》
CSCD
2017年第9期115-118,共4页
Netinfo Security
基金
国家自然科学基金[61472248]