Moving Target Defense Against Injection Attacks

被引:1
|
作者
Zhang, Huan [1 ]
Zheng, Kangfeng [1 ]
Yan, Xiaodan [1 ]
Luo, Shoushan [1 ]
Wu, Bin [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
关键词
Moving target defense; SQL injection attack; WEB service; Mutation period; Network security; TOOL;
D O I
10.1007/978-3-030-38991-8_34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of network technology, web services become more convenient and popular. However, web services are also facing serious security threats, especially SQL injection attack(SQLIA). Due to the diversity of attack techniques and the static of defense configurations, it is difficult for existing passive defence methods to effectively defend against all SQLIAs. To reduce the risk of successful SQLIAs and increase the difficulty of the attacker, an effective defence technique based on moving target defence (MTD) called dynamic defence to SQLIA (DTSA) was presented in this article. DTSA diversifies the types of databases and implementation languages dynamically, turns the Web server into an untraceable and unpredictable moving target and slows down SQLIAs. Moreover, the period of mutation was determined by the concept of dynamic programming so as to reduce the hazards caused by SQLIAs and minimize the impact on normal users as much as possible. Final, the experimental results showed that the proposed defence method can effectively defend against injection attacks in relational databases.
引用
收藏
页码:518 / 532
页数:15
相关论文
共 50 条
  • [1] Analysis of Moving Target Defense Against False Data Injection Attacks on Power Grid
    Zhang, Zhenyong
    Deng, Ruilong
    Yau, David K. Y.
    Cheng, Peng
    Chen, Jiming
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2320 - 2335
  • [2] On Hiddenness of Moving Target Defense against False Data Injection Attacks on Power Grid
    Zhang, Zhenyong
    Deng, Ruilong
    Yau, David K. Y.
    Cheng, Peng
    Chen, Jiming
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2020, 4 (03)
  • [3] Decentralized Moving Target Defense for Microgrid Protection Against False-Data Injection Attacks
    Giraldo, Jairo
    El Hariri, Mohamad
    Parvania, Masood
    IEEE TRANSACTIONS ON SMART GRID, 2022, 13 (05) : 3700 - 3710
  • [4] Optimal D-FACTS Placement in Moving Target Defense Against False Data Injection Attacks
    Liu, Bo
    Wu, Hongyu
    IEEE TRANSACTIONS ON SMART GRID, 2020, 11 (05) : 4345 - 4357
  • [5] Topology switching-based moving target defense against false data injection attacks on a power system
    Wang, Qi
    Wu, Shutan
    Wu, Zhong
    Hu, Jianxiong
    He, Quanpeng
    Ye, Yujian
    Tang, Yi
    INTERNATIONAL JOURNAL OF ELECTRICAL POWER & ENERGY SYSTEMS, 2024, 163
  • [6] Analysis of VM Migration Scheduling as Moving Target Defense against insider attacks
    Torquato, Matheus
    Maciel, Paulo
    Vieira, Marco
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 194 - 202
  • [7] Strategic Protection Against FDI Attacks With Moving Target Defense in Power Grids
    Zhang, Zhenyong
    Deng, Ruilong
    Cheng, Peng
    Chow, Mo-Yuen
    IEEE TRANSACTIONS ON CONTROL OF NETWORK SYSTEMS, 2022, 9 (01): : 245 - 256
  • [8] Incentive Compatible Moving Target Defense against VM-Colocation Attacks in Clouds
    Zhang, Yulong
    Li, Min
    Bai, Kun
    Yu, Meng
    Zang, Wanyu
    INFORMATION SECURITY AND PRIVACY RESEARCH, 2012, 376 : 388 - 399
  • [9] Securing IIoT systems against DDoS attacks with adaptive moving target defense strategies
    Swati
    Roy, Sangita
    Singh, Jawar
    Mathew, Jimson
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [10] Moving Target Defense Against Cross-Site Scripting Attacks (Position Paper)
    Portner, Joe
    Kerr, Joel
    Chu, Bill
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 85 - 91