• Home
  • Search
  • Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application
  • Cite Icon7
  • https://doi.org/10.1007/978-3-319-23276-8_14Copy DOI Icon

Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application

  • Jan 1, 2015
  • Nor Fatimah Awang +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Today almost all organizations have changed their traditional systems and have improved their performance using web-based applications. This process will make more profit and at the same time will increase the efficiency of their activities through customer support services and data transactions. Usually, web application take inputs from users through web form and send this input to get the response from database. Modern web-based application use web database to store all critical information such as user credentials, financial and payment information, company statistics etc. However error in validation of user input can cause database vulnerable to Structured Query Language Injection (SQLI) attack. By using SQLI attack, the attackers might insert malicious code in the user input and trying to gain access to the confidential and sensitive data from database. Security tester need to identify the appropriate test cases before starting exploiting SQL vulnerability in web-based application during testing phase. Identifying the test cases of a web application and analyzing the test results of an attack are important parts and consider as critical issues that affects the effectiveness of security testing. Thus, this research focused on the developing a framework for testing and detecting SQL injection vulnerability in web application. In this research, test cases will be generated automatically based on SQLI attack pattern and then the results will be executed automatically based on generated test cases. The primary focus in this paper is to develop a framework to automate security testing based on input injection attack pattern. To test our framework, we install a vulnerable web application and test result shows that the proposed framework can detect SQLI vulnerability successfully.

Similar Papers
  • Research Article
  • Citations13

Mitigation of SQL Injection Attacks using Threat Modeling

  • Dec 09, 2014
  • ACM SIGSOFT Software Engineering Notes
  • Navdeep Kaur +1
  • Conference Article
  • Citations13

Detecting SQL Injection On Web Application Using Deep Learning Techniques: A Systematic Literature Review

  • Oct 03, 2020
  • Muhammad Takdir Muslihi +1
  • Research Article
  • Citations76

An algorithm for detecting SQL injection vulnerability using black-box testing

  • Feb 07, 2019
  • Journal of Ambient Intelligence and Humanized Computing
  • Muhammad Saidu Aliero +3
  • Conference Article
  • Citations13

JCOMIX: a search-based tool to detect XML injection vulnerabilities in web applications

  • Aug 12, 2019
  • Dimitri Michel Stallenberg +1
  • Conference Article
  • Citations3

Attacks on Vulnerable Web Applications

  • Jun 25, 2021
  • Nikhil Kumar Singh +3
  • Research Article
  • Citations22

SQL injection attack: Detection, prioritization & prevention

  • Aug 31, 2024
  • Journal of Information Security and Applications
  • Alan Paul +2
  • Conference Article
  • Citations5

Web application database protection from SQLIA using permutation encoding

  • Mar 17, 2021
  • Mohammed Abdulridha Hussain +6
  • Research Article
  • Citations11

Combinatorial methods for dynamic gray‐box SQL injection testing

  • Jul 04, 2022
  • Software Testing, Verification and Reliability
  • Bernhard Garn +3
  • Conference Article

Research on Web application injection vulnerabilities detection method based on pattern matching

  • May 06, 2022
  • Qican Ma +3
  • Conference Article
  • Citations17

SQL-IDS

  • Sep 08, 2015
  • Naghmeh Moradpoor Sheykhkanloo
  • Research Article
  • Citations8

Nscanner: Vulnerabilities Detection Tool for Web Application

  • Dec 01, 2020
  • Journal of Physics: Conference Series
  • R Utaya Surian +2
  • Conference Article
  • Citations5

A security analysis tool for web application reinforcement against SQL injection attacks (SQLIAs)

  • Aug 01, 2013
  • Z Lashkaripour +1
  • Conference Article
  • Citations11

A Search-Based Testing Approach for XML Injection Vulnerabilities in Web Applications

  • Mar 01, 2017
  • Sadeeq Jan +3
  • Research Article
  • Citations7

SECURING WEB APPLICATIONS WITH OWASP ZAP FOR COMPREHENSIVE SECURITY TESTING

  • Dec 31, 2024
  • INTERNATIONAL JOURNAL OF ADVANCES IN SIGNAL AND IMAGE SCIENCES
  • S P Maniraj +2
  • Research Article
  • Citations2

DetAC: Approach to Detect Access Control Vulnerability in Web Application Based on Sitemap Model with Global Information Representation

  • Aug 31, 2023
  • International Journal of Software Engineering and Knowledge Engineering
  • Jiadong Ren +7
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.