2006
DOI: 10.1007/11663812_7
|View full text |Cite
|
Sign up to set email alerts
|

Defending Against Injection Attacks Through Context-Sensitive String Evaluation

Abstract: Abstract. Injection vulnerabilities pose a major threat to applicationlevel security. Some of the more common types are SQL injection, crosssite scripting and shell injection vulnerabilities. Existing methods for defending against injection attacks, that is, attacks exploiting these vulnerabilities, rely heavily on the application developers and are therefore error-prone. In this paper we introduce CSSE, a method to detect and prevent injection attacks. CSSE works by addressing the root cause why such attacks … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
175
0

Year Published

2006
2006
2015
2015

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 198 publications
(179 citation statements)
references
References 5 publications
(5 reference statements)
0
175
0
Order By: Relevance
“…The main means of attack Six out of the 12 gathered works [2,[11][12][13][14][15] involves classifying different types of WA injections.…”
Section: 2mentioning
confidence: 99%
See 4 more Smart Citations
“…The main means of attack Six out of the 12 gathered works [2,[11][12][13][14][15] involves classifying different types of WA injections.…”
Section: 2mentioning
confidence: 99%
“…All the studied works [2,[11][12][13][14][15] in one way or another discuss means of attack in terms of programming languages. This paper continues this tradition, using a categorization similar to that of [2].…”
Section: 2mentioning
confidence: 99%
See 3 more Smart Citations