Moving Target Defense Against Injection Attacks

被引:1
|
作者
Zhang, Huan [1 ]
Zheng, Kangfeng [1 ]
Yan, Xiaodan [1 ]
Luo, Shoushan [1 ]
Wu, Bin [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
关键词
Moving target defense; SQL injection attack; WEB service; Mutation period; Network security; TOOL;
D O I
10.1007/978-3-030-38991-8_34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of network technology, web services become more convenient and popular. However, web services are also facing serious security threats, especially SQL injection attack(SQLIA). Due to the diversity of attack techniques and the static of defense configurations, it is difficult for existing passive defence methods to effectively defend against all SQLIAs. To reduce the risk of successful SQLIAs and increase the difficulty of the attacker, an effective defence technique based on moving target defence (MTD) called dynamic defence to SQLIA (DTSA) was presented in this article. DTSA diversifies the types of databases and implementation languages dynamically, turns the Web server into an untraceable and unpredictable moving target and slows down SQLIAs. Moreover, the period of mutation was determined by the concept of dynamic programming so as to reduce the hazards caused by SQLIAs and minimize the impact on normal users as much as possible. Final, the experimental results showed that the proposed defence method can effectively defend against injection attacks in relational databases.
引用
收藏
页码:518 / 532
页数:15
相关论文
共 50 条
  • [31] Modeling Moving Target Defense strategies and attacks with SAN and ADVISE
    Mariotti, Francesco
    Manetti, Lorenzo
    Lollini, Paolo
    2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS, ISSREW, 2023, : 160 - 161
  • [32] Moving Target Defense Mechanism for Side-Channel Attacks
    Vuppala, Satyanarayana
    Mady, Alie El-Din
    Kuenzi, Adam
    IEEE SYSTEMS JOURNAL, 2020, 14 (02): : 1810 - 1819
  • [33] Defense Against Multi-target Trojan Attacks
    Harikumar, Haripriya
    Rana, Santu
    Do, Kien
    Gupta, Sunil
    Zong, Wei
    Susilo, Willy
    Venkastesh, Svetha
    arXiv, 2022,
  • [34] Decoy-based Moving Target defense Against Cyber-physical Attacks On Smart Grid
    Abdelwahab, Ahmed
    Lucia, Walter
    Youssef, Amr
    2020 IEEE ELECTRIC POWER AND ENERGY CONFERENCE (EPEC), 2020,
  • [35] A Double-Benefit Moving Target Defense Against Cyber-Physical Attacks in Smart Grid
    Zhang, Zhenyong
    Tian, Youliang
    Deng, Ruilong
    Ma, Jianfeng
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (18) : 17912 - 17925
  • [36] Efficient Strategy Selection for Moving Target Defense Under Multiple Attacks
    Zhang, Huan
    Zheng, Kangfeng
    Wang, Xiujuan
    Luo, Shoushan
    Wu, Bin
    IEEE ACCESS, 2019, 7 : 65982 - 65995
  • [37] A Moving Target Defense against Adversarial Machine Learning
    Roy, Abhishek
    Chhabra, Anshuman
    Kamhoua, Charles A.
    Mohapatra, Prasant
    SEC'19: PROCEEDINGS OF THE 4TH ACM/IEEE SYMPOSIUM ON EDGE COMPUTING, 2019, : 383 - 388
  • [38] Morphence: Moving Target Defense Against Adversarial Examples
    Amich, Abderrahmen
    Eshete, Birhanu
    37TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2021, 2021, : 61 - 75
  • [39] Investigation of Moving Target Defense Technique to Prevent Poisoning Attacks in SDN
    Macwan, Saumil
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 178 - 183
  • [40] Thwart Eavesdropping Attacks on Network Communication Based on Moving Target Defense
    Ma, Duohe
    Wang, Liming
    Lei, Cheng
    Xu, Zhen
    Zhang, Hongqi
    Li, Meng
    2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,