节点文献

SQL注入攻击途径及策略分析

SQL Injection Attack Way and Policy Analysis

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 高洪涛

【Author】 Gao Hongtao Department of Computer Investigation,China Criminal Police University,Liaoning,110854,China

【机构】 中国刑事警察学院

【摘要】 本文从SQL注入攻击的原理入手,对ASP+SQL Server网站攻击模型进行研究。从应用服务器、数据服务器、代码策略等角度进行测算,针对如何避免SQL注入进行策略分析。从功能程序角度,提出了通用SQL注入攻击检验模型,该模型策略可以在服务器端进行检测、跟踪、备案,保证用户访问服务器过程中以单独函数推进,保证系统处于稳定安全状态。

【Abstract】 In this paper,the principle of SQL injection attack was analyzed,and further,the attack model aiming at ASP+SQL Server website was discussed and measured from the point of application server,data servers and code strategies.The prevention strategies were given,so as to avoid the SQL injection.Finally,from the angle of function program,the general detection model of SQL injection attack was put forward in which we can detect,track the attack and record it in the server to ensure that users can access server in separate function propulsion,guarantee system in a stable condition.

【关键词】 SQL注入攻击策略分析检测模型
【Key words】 SQLInjection AttackStrategy AnalysisDetection Model
  • 【文献出处】 网络安全技术与应用 ,Network Security Technology & Application , 编辑部邮箱 ,2011年03期
  • 【分类号】TP393.08
  • 【被引频次】25
  • 【下载频次】378
节点文献中: 

本文链接的文献网络图示:

本文的引文网络