UPM Institutional Repository

Model-based system architecture for preventing XPath injection in database-centric web services environment


Citation

Asmawi, Aziah and Affendey, Lilly Suriani and Udzir, Nur Izura and Mahmod, Ramlan (2012) Model-based system architecture for preventing XPath injection in database-centric web services environment. In: 7th International Conference on Computing and Convergence Technology (ICCCT 2012), 3-5 Dec. 2012, Seoul, Korea. (pp. 621-625).

Abstract

Web services have become a powerful interface for back-end database systems. It is a self-describing component that can be used by other applications in a platform-independent manner. However, along the benefit of Web services, comes a serious risk of security breaches. Most web services are deployed with security flaws and these vulnerabilities make them exposed to XPath (XML Path Language) injection. This kind of attack can cause serious damage to the database at the backend of web services. This paper proposes a system architecture for prevention mechanism against XPath injection attacks within web services. The prevention mechanism employs the model-based approach to detect malicious queries and prevent them before they are executed on the web services backend database. This approach uses runtime monitoring to check on the dynamically-generated queries and compares them against the statistically-built model.


Download File

[img]
Preview
PDF (Abstract)
Model-based system architecture for preventing XPath injection in database-centric web services environment.pdf

Download (36kB) | Preview

Additional Metadata

Item Type: Conference or Workshop Item (Paper)
Divisions: Faculty of Computer Science and Information Technology
Publisher: IEEE
Keywords: Database security; Non-deterministic finite automata; Static analysis; Stored procedures; Web services; XPath injection
Depositing User: Nabilah Mustapa
Date Deposited: 14 Jul 2016 04:40
Last Modified: 14 Jul 2016 04:40
URI: http://psasir.upm.edu.my/id/eprint/47685
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item