Sciweavers

11 search results - page 1 / 3
» CANDID: Dynamic candidate evaluations for automatic preventi...
Sort
View
TISSEC
2010
109views more  TISSEC 2010»
13 years 3 months ago
CANDID: Dynamic candidate evaluations for automatic prevention of SQL injection attacks
Prithvi Bisht, Parthasarathy Madhusudan, V. N. Ven...
CCS
2007
ACM
13 years 8 months ago
CANDID: preventing sql injection attacks using dynamic candidate evaluations
Sruthi Bandhakavi, Prithvi Bisht, P. Madhusudan, V...
ASWEC
2006
IEEE
13 years 11 months ago
Preventing SQL Injection Attacks in Stored Procedures
An SQL injection attack targets interactive web applications that employ database services. These applications accept user inputs and use them to form SQL statements at runtime. D...
Ke Wei, Muthusrinivasan Muthuprasanna, Suraj Kotha...
SAC
2009
ACM
13 years 11 months ago
SQLProb: a proxy-based architecture towards preventing SQL injection attacks
SQL injection attacks (SQLIAs) consist of maliciously crafted SQL inputs, including control code, used against Databaseconnected Web applications. To curtail the attackers’ abil...
Anyi Liu, Yi Yuan, Duminda Wijesekera, Angelos Sta...
IJSSE
2010
121views more  IJSSE 2010»
13 years 2 months ago
Retrofitting Existing Web Applications with Effective Dynamic Protection Against SQL Injection Attacks
This paper presents an approach for retrofitting existing web applications with runtime protection against known as well as unseen SQL injection attacks (SQLIAs) without the invol...
San-Tsai Sun, Konstantin Beznosov