conference-paper Open access

Synthesis of Allowlists for Runtime Protection against SQLi

Research footprint

At a glance

Citations
1
References
9
Comments
0
Paper overview

Öz

Data is the new oil. This metaphor is commonly used to highlight the fact that data is a highly valuable commodity. Nowadays, much of worldwide data sits in SQL databases and transits through various web-based applications. As the value of data increases and attracts more attention from malicious actors, application protections against SQL injections need to become more sophisticated. Although SQL injections have been known for many years, they are still one of the top security vulnerabilities. For example, in 2022 more than 1000 CVEs related to SQL injection were reported. We propose a runtime application protection approach that infers and constrains the information that can be disclosed by database-backed applications. Where existing approaches use syntax or hand-crafted features as a proxy for information disclosure, we propose a lightweight, but precise, information disclosure model that faithfully captures the semantics of SQL and achieves finer-grain security.

Record transparency

Publication details

DOI
10.1145/3639476.3639772
OpenAlex
W4398785910
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.