Policy-based SQLIA detection and prevention approach for RFID systems


Autoria(s): Abawajy, Jemal; Fernando, Harinda
Data(s)

01/02/2015

Resumo

While SQL injection attacks have been plaguing web application systems for years, the possibility of them affecting RFID systems was only identified very recently. However, very little work exists to mitigate this serious security threat to RFID-enabled enterprise systems. In this paper, we propose a policy-based SQLIA detection and prevention method for RFID systems. The proposed technique creates data validation and sanitization policies during content analysis and enforces those policies during runtime monitoring. We tested all possible types of dynamic queries that may be generated in RFID systems with all possible types of attacks that can be mounted on those systems. We present an analysis and evaluation of the proposed approach to demonstrate the effectiveness of the proposed approach in mitigating SQLIA.

Identificador

http://hdl.handle.net/10536/DRO/DU:30070782

Idioma(s)

eng

Publicador

Elsevier

Relação

http://dro.deakin.edu.au/eserv/DU:30070782/abawajy-policybased-2015.pdf

http://www.dx.doi.org/10.1016/j.csi.2014.08.005

Direitos

2015, Elsevier

Palavras-Chave #Science & Technology #Technology #Computer Science, Hardware & Architecture #Computer Science, Software Engineering #Computer Science #RFID #SQLIA #Data validation #Data sanitization #Policy #INJECTION ATTACKS #MALWARE
Tipo

Journal Article