Moving Target Defense Against Injection Attacks

被引:1
|
作者
Zhang, Huan [1 ]
Zheng, Kangfeng [1 ]
Yan, Xiaodan [1 ]
Luo, Shoushan [1 ]
Wu, Bin [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
关键词
Moving target defense; SQL injection attack; WEB service; Mutation period; Network security; TOOL;
D O I
10.1007/978-3-030-38991-8_34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of network technology, web services become more convenient and popular. However, web services are also facing serious security threats, especially SQL injection attack(SQLIA). Due to the diversity of attack techniques and the static of defense configurations, it is difficult for existing passive defence methods to effectively defend against all SQLIAs. To reduce the risk of successful SQLIAs and increase the difficulty of the attacker, an effective defence technique based on moving target defence (MTD) called dynamic defence to SQLIA (DTSA) was presented in this article. DTSA diversifies the types of databases and implementation languages dynamically, turns the Web server into an untraceable and unpredictable moving target and slows down SQLIAs. Moreover, the period of mutation was determined by the concept of dynamic programming so as to reduce the hazards caused by SQLIAs and minimize the impact on normal users as much as possible. Final, the experimental results showed that the proposed defence method can effectively defend against injection attacks in relational databases.
引用
收藏
页码:518 / 532
页数:15
相关论文
共 50 条
  • [21] A Cost-effective Shuffling Method against DDoS Attacks using Moving Target Defense
    Zhou, Yuyang
    Cheng, Guang
    Jiang, Shanqing
    Hu, Ying
    Zhao, Yuyu
    Chen, Zihan
    PROCEEDINGS OF THE 6TH ACM WORKSHOP ON MOVING TARGET DEFENSE, MTD 2019, 2019, : 57 - 66
  • [22] MTDeep: Boosting the Security of Deep Neural Nets Against Adversarial Attacks with Moving Target Defense
    Sengupta, Sailik
    Chakraborti, Tathagata
    Kambhampati, Subbarao
    DECISION AND GAME THEORY FOR SECURITY, 2019, 11836 : 479 - 491
  • [23] A Bayesian Nash Equilibrium-Based Moving Target Defense Against Stealthy Sensor Attacks
    Umsonst, David
    Sartas, Serkan
    Dan, Gyorgy
    Sandberg, Henrik
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2024, 69 (03) : 1659 - 1674
  • [24] VM Migration Scheduling as Moving Target Defense against Memory DoS Attacks: An Empirical Study
    Torquato, Matheus
    Vieira, Marco
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [25] Towards Cost-Effective Moving Target Defense Against DDoS and Covert Channel Attacks
    Wang, Huangxin
    Li, Fei
    Chen, Songqing
    MTD'16: PROCEEDINGS OF THE 2016 ACM WORKSHOP ON MOVING TARGET DEFENSE, 2016, : 15 - 25
  • [26] MTDroid: A Moving Target Defense-Based Android Malware Detector Against Evasion Attacks
    Zhou, Yuyang
    Cheng, Guang
    Yu, Shui
    Chen, Zongyao
    Hu, Yujia
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6377 - 6392
  • [27] On the Resilience of Network-based Moving Target Defense Techniques Against Host Profiling Attacks
    Piskozub, Michal
    Spolaor, Riccardo
    Conti, Mauro
    Martinovic, Ivan
    PROCEEDINGS OF THE 6TH ACM WORKSHOP ON MOVING TARGET DEFENSE, MTD 2019, 2019, : 1 - 12
  • [28] A Moving Target Defense Approach to Mitigate DDoS Attacks against Proxy-Based Architectures
    Venkatesan, Sridhar
    Albanese, Massimiliano
    Amin, Kareem
    Jajodia, Sushil
    Wright, Mason
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 198 - 206
  • [29] Hidden Moving Target Defense against False Data Injection in Distribution Network Reconfiguration
    Liu, Bo
    Wu, Hongyu
    Pahwa, Anil
    Ding, Fei
    Ibrahim, Erfan
    Liu, Ting
    2018 IEEE POWER & ENERGY SOCIETY GENERAL MEETING (PESGM), 2018,
  • [30] Preventing SSH Remote Attacks Using Moving Target Defense
    Heydari, Vahid
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 272 - 280