Research of methods of automated search of “sql injection” type vulnerabilities in web applications

Yevhenii Berloh, ,Andrii Rohovenko,Hanna Dyvnych, ,

Technical Sciences and Technologies(2022)

引用 0|浏览0
暂无评分
摘要
The article presents the results of a scientific and methodological study of the methods of automated search for SQL vulnerabilities in web applications. An example of an attack using a typical SQL injection is provided. The classification ofweb application security assessment methods based on penetration testing is given. The results of practical studies of the operation of the most widely used web scanners for automated vulnerability testing of web applications are given. Based on the results, a comparison of the effectiveness of penetration testing methods has been made. The possible directions of further research into the methods of automated search for SQL vulnerabilities in web applications are substantiated, taking into ac-count the results obtained, in particular the values of the Youden Index.
更多
查看译文
关键词
sql injection”,type vulnerabilities,web applications,automated research
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要