loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Mohammad Qbea’h 1 ; Saed Alrabaee 1 and Djedjiga Mouheb 2

Affiliations: 1 Information Systems and Security, College of IT, United Arab Emirates University, Al Ain, Abu Dhabi, U.A.E. ; 2 Department of Computer Science, College of Computing and Informatics, University of Sharjah, U.A.E.

Keyword(s): SQL Injection Attack, Cross Site Scripting, Encoding, Base64 Encoding, XSS, Hex Encodings, SQLIA, Android Attack.

Abstract: Among the most critical and dangerous attacks is the one that exploits Base64 or Hex encoding technique in SQL Injection (SQLIA) and Cross Site Scripting (XSS) attacks, instead of using plain text. This technique is widely used in most dangerous attacks because it evades detection. Therefore, it is possible to bypass many filters such as IDS, without taking into account the transformation methodologies of the symbols and characters. Moreover, it reserves the same semantics with different syntax. Attackers can exploit this serious technique to reach unseen data and gain valuable benefits. To the best of our knowledge, this paper presents the first technique that focuses on detecting and preventing transformed SQLIA and XSS from Base64 and Hex encoding. We perform scanning and analyzing methods by targeting two places: (i) Input boxes and (ii) Strings in page URLs. Then, we decode the inputs and compare them with our stored suspicious tokens. Finally, we perform string matching and mut ation mechanisms to revoke the activity of malicious inputs. We have evaluated our technique and the results showed that it is capable to detect and prevent this transformed attack. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.19.31.73

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Qbea’h, M.; Alrabaee, S. and Mouheb, D. (2020). An Analytical Scanning Technique to Detect and Prevent the Transformed SQL Injection and XSS Attacks. In Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-399-5; ISSN 2184-4356, SciTePress, pages 603-610. DOI: 10.5220/0009004006030610

@conference{icissp20,
author={Mohammad Qbea’h. and Saed Alrabaee. and Djedjiga Mouheb.},
title={An Analytical Scanning Technique to Detect and Prevent the Transformed SQL Injection and XSS Attacks},
booktitle={Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP},
year={2020},
pages={603-610},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0009004006030610},
isbn={978-989-758-399-5},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP
TI - An Analytical Scanning Technique to Detect and Prevent the Transformed SQL Injection and XSS Attacks
SN - 978-989-758-399-5
IS - 2184-4356
AU - Qbea’h, M.
AU - Alrabaee, S.
AU - Mouheb, D.
PY - 2020
SP - 603
EP - 610
DO - 10.5220/0009004006030610
PB - SciTePress