Securing RFID systems from SQLIA


Autoria(s): Fernando, Harinda; Abawajy, Jemal
Contribuinte(s)

Xiang, Yang

Cuzzocrea, Alfredo

Hobbs, Michael

Zhou, Wanlei

Data(s)

01/01/2011

Resumo

While SQL injection attacks have been plaguing web applications for years the threat they pose to RFID systems have only identified recently. Because the architecture of web systems and RFID systems differ considerably the prevention and detection techniques proposed for web applications are not suitable for RFID systems. In this paper we propose a system to secure RFID systems against tag based SQLIA. Our system is optimized for the architecture of RFID systems and consists of a query structure matching technique and tag data cleaning technique. The novelty of the proposed system is that it's specifically aimed at RFID systems and has the ability to detect and prevent second order injections which is a problem most current solutions haven't addressed. The preliminary evaluation of our query matching technique is very promising showing very high detection rate with minimal false positives.<br />

Identificador

http://hdl.handle.net/10536/DRO/DU:30043145

Idioma(s)

eng

Publicador

Springer-Verlag

Relação

http://dro.deakin.edu.au/eserv/DU:30043145/fernando-securingrfid-2011.pdf

http://dro.deakin.edu.au/eserv/DU:30043145/fernando-securingrfid-evidence-2011.pdf

http://hdl.handle.net/10.1007/978-3-642-24669-2_24

Direitos

2011, Springer-Verlag Berlin

Palavras-Chave #SQL #RFID systems #web systems
Tipo

Book Chapter