Title: Analysis and implementation of SQL injection attack and countermeasures using SQL injection prevention techniques

Authors: A. Jesudoss; Theresa M. Mercy; A. Christy; M. Maheswari; M. Selvi; V. Ulagamuthalvi

Addresses: Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, Tamil Nadu, India ' Department of Electronics and Communication Engineering, Prince Shri Venkateswara Padmavathy Engineering College, Chennai, Tamil Nadu, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India ' Department of Computer Science and Engineering, School of Computing, Sathyabama Institute of Science and Technology, Chennai, India

Abstract: SQL injection attack is the most critical and very common attack to security of web applications. The paper analyses the vulnerabilities that arise due to SQL injection attacks and presents consolidated prevention techniques which consider all vulnerabilities and identifies the SQL injection attacks. It also provides appropriate solution for safeguarding against SQL injection attacks. While being cost-effective, these prevention techniques are also easy to configure, administer and implement. Experimental results have proven that these prevention techniques efficiently identify and protect against SQL injection attacks. The prevention techniques discussed in this paper have been implemented and tested effectively. The results of testing are satisfactory.

Keywords: SQL injection; malicious input; validation; web application firewall; injection attack.

DOI: 10.1504/IJESMS.2022.126305

International Journal of Engineering Systems Modelling and Simulation, 2022 Vol.13 No.4, pp.262 - 267

Received: 08 Apr 2021
Accepted: 16 Aug 2021

Published online: 19 Oct 2022 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article