Repository logo
 
Publication

Query log analysis for SQL injection detection

dc.contributor.authorRocha, Alexandra
dc.contributor.authorAlves, Rui
dc.contributor.authorPedrosa, Tiago
dc.date.accessioned2024-01-05T10:06:10Z
dc.date.available2024-01-05T10:06:10Z
dc.date.issued2023
dc.description.abstractNowadays, more and more services are dependent on the use of resources hosted on the web. The realization of operations such as access to the account bank, credit card operations, among other operations, is something increasingly common in current times, demonstrating not only human dependence on the internet connection, as well as the need to adapt the web resources to the daily life of society. As a result of this growing dependency, web resources now provide a greater amount of confidential information, making the risk of a cyberattack and information leaking grow considerably. In the web context, one of the most well-known attacks is SQL injection that allows the attacker to exploit, through the injection of malicious queries, access to confidential information. This paper suggests a solution for the detection of SQL injection via web resources, using the analysis of the logs of the executed queries.pt_PT
dc.description.sponsorshipThis work was partially supported by the Norte Portugal Regional Operational Programme(NORTE 2020), under the PORTUGAL 2020 Partnership Agreement, through the European Regional Development Fund (ERDF), within project “CybersSe- CIP” (NORTE-01-0145-FEDER-000044). The authors are grateful to the Foundation for Science and Technology (FCT, Portugal) for financial support through national funds FCT/MCTES (PIDDAC) to CeDRI (UIDB/05757/2020 and UIDP/05757/2020) and SusTEC (LA/P/0007/2021).pt_PT
dc.description.versioninfo:eu-repo/semantics/publishedVersionpt_PT
dc.identifier.citationRocha, Alexandra; Alves, Rui; Pedrosa, Tiago (2023). Query log analysis for SQL injection detection. In Proceedings of the 9th International Conference on Information Systems Security and Privacy (ICISSP). 22-24 February 2023, Lisbon. ISSN 2184-4356. 1, p. 471-476pt_PT
dc.identifier.doi10.5220/0011667200003405pt_PT
dc.identifier.isbn978989758624-8
dc.identifier.issn2184-4356
dc.identifier.urihttp://hdl.handle.net/10198/29101
dc.language.isoengpt_PT
dc.peerreviewedyespt_PT
dc.relationLA/P/0007/2021pt_PT
dc.relationResearch Centre in Digitalization and Intelligent Robotics
dc.relationResearch Centre in Digitalization and Intelligent Robotics
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/pt_PT
dc.subjectSQL Injectionpt_PT
dc.subjectIDSpt_PT
dc.subjectMySQLpt_PT
dc.subjectAttackspt_PT
dc.subjectDetectionpt_PT
dc.titleQuery log analysis for SQL injection detectionpt_PT
dc.typeconference object
dspace.entity.typePublication
oaire.awardTitleResearch Centre in Digitalization and Intelligent Robotics
oaire.awardTitleResearch Centre in Digitalization and Intelligent Robotics
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F05757%2F2020/PT
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDP%2F05757%2F2020/PT
oaire.citation.endPage476pt_PT
oaire.citation.startPage471pt_PT
oaire.citation.titleProceedings of the 9th International Conference on Information Systems Security and Privacy (ICISSP)pt_PT
oaire.citation.volume1pt_PT
oaire.fundingStream6817 - DCRRNI ID
oaire.fundingStream6817 - DCRRNI ID
person.familyNameAlves
person.familyNamePedrosa
person.givenNameRui
person.givenNameTiago
person.identifier.ciencia-idA716-1D09-38A0
person.identifier.ciencia-idB81E-0583-AEDF
person.identifier.orcid0000-0003-4128-8779
person.identifier.orcid0000-0003-4873-2705
person.identifier.ridG-2249-2011
person.identifier.scopus-author-id57219876713
person.identifier.scopus-author-id35318153700
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.nameFundação para a Ciência e a Tecnologia
project.funder.nameFundação para a Ciência e a Tecnologia
rcaap.rightsopenAccesspt_PT
rcaap.typeconferenceObjectpt_PT
relation.isAuthorOfPublication59025c90-9178-412c-ae43-fe1a6122c72a
relation.isAuthorOfPublicationfee2835e-2230-4414-a58e-bcba895d1f0b
relation.isAuthorOfPublication.latestForDiscovery59025c90-9178-412c-ae43-fe1a6122c72a
relation.isProjectOfPublication6e01ddc8-6a82-4131-bca6-84789fa234bd
relation.isProjectOfPublicationd0a17270-80a8-4985-9644-a04c2a9f2dff
relation.isProjectOfPublication.latestForDiscoveryd0a17270-80a8-4985-9644-a04c2a9f2dff

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
116672.pdf
Size:
357.76 KB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.75 KB
Format:
Item-specific license agreed upon to submission
Description: