UPM Institutional Repository

XIPS : a model-based prevention mechanism for preventing blind XPath injection in database-centric web services environment.


Citation

Asmawi, Aziah and Affendey, Lilly Suriani and Udzir, Nur Izura and Mahmod, Ramlan (2013) XIPS : a model-based prevention mechanism for preventing blind XPath injection in database-centric web services environment. International Journal of Advancements in Computing Technology, 5 (10). pp. 69-77. ISSN 2005-8039; ESSN:2233-9337

Abstract

Web services have become a powerful interface for backend database systems which provides many services such as automatic purchasing, inventory tracking and clinical management. However, along the benefit of Web services, comes a serious risk of security breaches. Most Web services are deployed with security flaws and these vulnerabilities expose them to XPath (XML Path Language) injection. This kind of attack can cause serious damage to the database at the back end of Web services. This paper proposes XIPS, a prevention mechanism against Blind XPath injection attacks within Web services environment. The prevention mechanism employs the model-based approach to detect malicious queries and thwart them before they are executed on the Web services back end database. This approach uses run time monitoring to check on the dynamically-generated queries and compares them against the statistically-built model. The employment of the XIPS architecture should be able to prevent Web services from any kinds of XPath injection attacks.


Download File

[img]
Preview
PDF (Abstract)
XIPS.pdf

Download (85kB) | Preview

Additional Metadata

Item Type: Article
Divisions: Faculty of Computer Science and Information Technology
Publisher: Advanced Institute of Convergence Information Technology
Keywords: Web services; Database security; Blind XPath injection; Model-based; Hotspot.
Depositing User: Ms. Nida Hidayati Ghazali
Date Deposited: 14 Jul 2014 07:12
Last Modified: 07 Sep 2015 03:41
URI: http://psasir.upm.edu.my/id/eprint/30654
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item