Automated security testing framework for detecting SQL injection vulnerability in web application

Today almost all organizations have changed their traditional systems and have improved their performance using web-based applications. This process will make more profit and at the same time will increase the efficiency of their activities through customer support services and data transactions. Us...

Full description

Saved in:
Bibliographic Details
Main Authors: Awang, N. F., Manaf, A. A.
Format: Conference or Workshop Item
Published: 2015
Subjects:
Online Access:http://eprints.utm.my/id/eprint/59166/
http://dx.doi.org/10.1007/978-3-319-23276-8_14
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utm.59166
record_format eprints
spelling my.utm.591662021-12-08T08:02:16Z http://eprints.utm.my/id/eprint/59166/ Automated security testing framework for detecting SQL injection vulnerability in web application Awang, N. F. Manaf, A. A. T Technology (General) Today almost all organizations have changed their traditional systems and have improved their performance using web-based applications. This process will make more profit and at the same time will increase the efficiency of their activities through customer support services and data transactions. Usually, web application take inputs from users through web form and send this input to get the response from database. Modern web-based application use web database to store all critical information such as user credentials, financial and payment information, company statistics etc. However error in validation of user input can cause database vulnerable to Structured Query Language Injection (SQLI) attack. By using SQLI attack, the attackers might insert malicious code in the user input and trying to gain access to the confidential and sensitive data from database. Security tester need to identify the appropriate test cases before starting exploiting SQL vulnerability in web-based application during testing phase. Identifying the test cases of a web application and analyzing the test results of an attack are important parts and consider as critical issues that affects the effectiveness of security testing. Thus, this research focused on the developing a framework for testing and detecting SQL injection vulnerability in web application. In this research, test cases will be generated automatically based on SQLI attack pattern and then the results will be executed automatically based on generated test cases. The primary focus in this paper is to develop a framework to automate security testing based on input injection attack pattern. To test our framework, we install a vulnerable web application and test result shows that the proposed framework can detect SQLI vulnerability successfully. 2015 Conference or Workshop Item PeerReviewed Awang, N. F. and Manaf, A. A. (2015) Automated security testing framework for detecting SQL injection vulnerability in web application. In: Global Security, Safety and Sustainability: Tomorrow's Challenges of Cyber Security - 10th International Conference, ICGS3 2015, 15 - 17 September 2015, London, United Kingdom. http://dx.doi.org/10.1007/978-3-319-23276-8_14
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
topic T Technology (General)
spellingShingle T Technology (General)
Awang, N. F.
Manaf, A. A.
Automated security testing framework for detecting SQL injection vulnerability in web application
description Today almost all organizations have changed their traditional systems and have improved their performance using web-based applications. This process will make more profit and at the same time will increase the efficiency of their activities through customer support services and data transactions. Usually, web application take inputs from users through web form and send this input to get the response from database. Modern web-based application use web database to store all critical information such as user credentials, financial and payment information, company statistics etc. However error in validation of user input can cause database vulnerable to Structured Query Language Injection (SQLI) attack. By using SQLI attack, the attackers might insert malicious code in the user input and trying to gain access to the confidential and sensitive data from database. Security tester need to identify the appropriate test cases before starting exploiting SQL vulnerability in web-based application during testing phase. Identifying the test cases of a web application and analyzing the test results of an attack are important parts and consider as critical issues that affects the effectiveness of security testing. Thus, this research focused on the developing a framework for testing and detecting SQL injection vulnerability in web application. In this research, test cases will be generated automatically based on SQLI attack pattern and then the results will be executed automatically based on generated test cases. The primary focus in this paper is to develop a framework to automate security testing based on input injection attack pattern. To test our framework, we install a vulnerable web application and test result shows that the proposed framework can detect SQLI vulnerability successfully.
format Conference or Workshop Item
author Awang, N. F.
Manaf, A. A.
author_facet Awang, N. F.
Manaf, A. A.
author_sort Awang, N. F.
title Automated security testing framework for detecting SQL injection vulnerability in web application
title_short Automated security testing framework for detecting SQL injection vulnerability in web application
title_full Automated security testing framework for detecting SQL injection vulnerability in web application
title_fullStr Automated security testing framework for detecting SQL injection vulnerability in web application
title_full_unstemmed Automated security testing framework for detecting SQL injection vulnerability in web application
title_sort automated security testing framework for detecting sql injection vulnerability in web application
publishDate 2015
url http://eprints.utm.my/id/eprint/59166/
http://dx.doi.org/10.1007/978-3-319-23276-8_14
_version_ 1720436900440834048
score 13.18916