NoSQL Injection Attack Detection in Web Applications Using RESTful Service
- 作者: Eassa A.M.1,2, Elhoseny M.1, El-Bakry H.M.1, Salama A.S.3,4
-
隶属关系:
- Faculty of Computers and Information, Mansoura University
- Management Information Systems Department, Faculty of Management, MTI University
- Computer and Information Systems Department, Sadat Academy for Management Sciences
- Information Systems Department, Faculty of Computing and Information Technology, University of Jeddah
- 期: 卷 44, 编号 6 (2018)
- 页面: 435-444
- 栏目: Article
- URL: https://journals.rcsi.science/0361-7688/article/view/176691
- DOI: https://doi.org/10.1134/S036176881901002X
- ID: 176691
如何引用文章
详细
Despite the extensive research of using web services for security purposes, there is a big challenge towards finding a no radical solution for NoSQL injection attack. This paper presents an independent RESTful web service in a layered approach to detect NoSQL injection attacks in web applications. The proposed method is named DNIARS. DNIARS depends on comparing the generated patterns from NoSQL statement structure in static code state and dynamic state. Accordingly, the DNIARS can respond to the web application with the possibility of NoSQL injection attack. The proposed DNIARS was implemented in PHP plain code and can be considered as an independent framework that has the ability for responding to different requests formats like JSON, XML. To evaluate its performance, DNIARS was tested using the most common testing tools for RESTful web service. According to the results, DNIARS can work in real environments where the error rate did not exceed 1%.
作者简介
Ahmed Eassa
Faculty of Computers and Information, Mansoura University; Management Information Systems Department, Faculty of Management, MTI University
编辑信件的主要联系方式.
Email: ahmed.mti@outlook.com
埃及, Mansoura; Cairo
Mohamed Elhoseny
Faculty of Computers and Information, Mansoura University
Email: ahmed.mti@outlook.com
埃及, Mansoura
Hazem El-Bakry
Faculty of Computers and Information, Mansoura University
Email: ahmed.mti@outlook.com
埃及, Mansoura
Ahmed Salama
Computer and Information Systems Department, Sadat Academy for Management Sciences; Information Systems Department, Faculty of Computing and Information Technology, University of Jeddah
Email: ahmed.mti@outlook.com
埃及, Cairo; Jeddah
补充文件
