HTTP Request - SQL Query Mapping Scheme for Malicious SQL Query Detection in Multitier Web Applications 


Vol. 44,  No. 1, pp. 1-12, Jan.  2017


PDF

  Abstract

The continuously growing internet service requirements has resulted in a multitier system structure consisting of web server and database (DB) server. In this multitier structure, the existing intrusion detection system (IDS) detects known attacks by matching misused traffic patterns or signatures. However, malicious change to the contents at DB server through hypertext transfer protocol (HTTP) requests at the DB server cannot be detected by the IDS at the DB server’s end, since the DB server processes structured query language (SQL) without knowing the associated HTTP, while the web server cannot identify the response associated with the attacker’s SQL query. To detect these types of attacks, the malicious user is tracked using knowledge on interaction between HTTP request and SQL query. However, this is a practical challenge because system’s source code analysis and its application logic needs to be understood completely. In this study, we proposed a scheme to find the HTTP request associated with a given SQL query using only system log files. We first generated an HTTP request-SQL query map from system log files alone. Subsequently, the HTTP request associated with a given SQL query was identified among a set of HTTP requests using this map. Computer simulations indicated that the proposed scheme finds the HTTP request associated with a given SQL query with 94% accuracy.


  Statistics
Cumulative Counts from November, 2022
Multiple requests among the same browser session are counted as one view. If you mouse over a chart, the values of data points will be shown.


  Cite this article

[IEEE Style]

Y. Seo and S. Park, "HTTP Request - SQL Query Mapping Scheme for Malicious SQL Query Detection in Multitier Web Applications," Journal of KIISE, JOK, vol. 44, no. 1, pp. 1-12, 2017. DOI: .


[ACM Style]

Yeongung Seo and Seungyoung Park. 2017. HTTP Request - SQL Query Mapping Scheme for Malicious SQL Query Detection in Multitier Web Applications. Journal of KIISE, JOK, 44, 1, (2017), 1-12. DOI: .


[KCI Style]

서영웅, 박승영, "Multitier 웹 어플리케이션 환경에서 악의적인 SQL Query 탐지를 위한 HTTP Request - SQL Query 매핑 기법," 한국정보과학회 논문지, 제44권, 제1호, 1~12쪽, 2017. DOI: .


[Endnote/Zotero/Mendeley (RIS)]  Download


[BibTeX]  Download



Search




Journal of KIISE

  • ISSN : 2383-630X(Print)
  • ISSN : 2383-6296(Electronic)
  • KCI Accredited Journal

Editorial Office

  • Tel. +82-2-588-9240
  • Fax. +82-2-521-1352
  • E-mail. chwoo@kiise.or.kr