CN107122657B - 一种防御sql注入攻击的数据库代理装置 - Google Patents
一种防御sql注入攻击的数据库代理装置 Download PDFInfo
- Publication number
- CN107122657B CN107122657B CN201710301809.1A CN201710301809A CN107122657B CN 107122657 B CN107122657 B CN 107122657B CN 201710301809 A CN201710301809 A CN 201710301809A CN 107122657 B CN107122657 B CN 107122657B
- Authority
- CN
- China
- Prior art keywords
- statement
- sql
- module
- statements
- attack
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer And Data Communications (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710301809.1A CN107122657B (zh) | 2017-05-02 | 2017-05-02 | 一种防御sql注入攻击的数据库代理装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710301809.1A CN107122657B (zh) | 2017-05-02 | 2017-05-02 | 一种防御sql注入攻击的数据库代理装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN107122657A CN107122657A (zh) | 2017-09-01 |
CN107122657B true CN107122657B (zh) | 2021-01-01 |
Family
ID=59726674
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201710301809.1A Active CN107122657B (zh) | 2017-05-02 | 2017-05-02 | 一种防御sql注入攻击的数据库代理装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN107122657B (zh) |
Families Citing this family (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107644175A (zh) * | 2017-09-13 | 2018-01-30 | 南京南瑞集团公司 | 一种防止sql注入的方法 |
CN107483510B (zh) * | 2017-10-09 | 2020-11-24 | 杭州安恒信息技术股份有限公司 | 一种提高Web应用层攻击检测准确率的方法及装置 |
CN108388802A (zh) * | 2018-03-21 | 2018-08-10 | 中国人民解放军战略支援部队信息工程大学 | 一种脚本注入攻击的告警方法及告警系统 |
CN110162974B (zh) * | 2019-05-28 | 2021-03-30 | 郑州昂视信息科技有限公司 | 数据库攻击防御方法及系统 |
CN112182018B (zh) * | 2020-10-16 | 2023-04-21 | 华东计算技术研究所(中国电子科技集团公司第三十二研究所) | 面向web应用的拟态构造数据库访问系统及方法 |
Citations (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101388763A (zh) * | 2007-09-12 | 2009-03-18 | 北京启明星辰信息技术有限公司 | 一种支持多种数据库类型的sql注入攻击检测系统 |
WO2012063493A1 (ja) * | 2010-11-10 | 2012-05-18 | 京セラコミュニケーションシステム株式会社 | 脆弱性診断装置 |
CN103559444A (zh) * | 2013-11-05 | 2014-02-05 | 星云融创(北京)信息技术有限公司 | 一种sql注入检测方法及装置 |
CN104008349A (zh) * | 2014-04-28 | 2014-08-27 | 国家电网公司 | 数据库安全访问控制方法和系统 |
CN104123497A (zh) * | 2014-07-04 | 2014-10-29 | 北京神州绿盟信息安全科技股份有限公司 | 一种防御sql注入的方法、装置及系统 |
CN104537307A (zh) * | 2014-12-23 | 2015-04-22 | 北京奇虎科技有限公司 | 网站漏洞检测方法和系统 |
CN106355094A (zh) * | 2016-07-08 | 2017-01-25 | 耿童童 | 一种基于语法变换的sql注入攻击防御系统及防御方法 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8615804B2 (en) * | 2010-02-18 | 2013-12-24 | Polytechnic Institute Of New York University | Complementary character encoding for preventing input injection in web applications |
-
2017
- 2017-05-02 CN CN201710301809.1A patent/CN107122657B/zh active Active
Patent Citations (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101388763A (zh) * | 2007-09-12 | 2009-03-18 | 北京启明星辰信息技术有限公司 | 一种支持多种数据库类型的sql注入攻击检测系统 |
WO2012063493A1 (ja) * | 2010-11-10 | 2012-05-18 | 京セラコミュニケーションシステム株式会社 | 脆弱性診断装置 |
CN103559444A (zh) * | 2013-11-05 | 2014-02-05 | 星云融创(北京)信息技术有限公司 | 一种sql注入检测方法及装置 |
CN104008349A (zh) * | 2014-04-28 | 2014-08-27 | 国家电网公司 | 数据库安全访问控制方法和系统 |
CN104123497A (zh) * | 2014-07-04 | 2014-10-29 | 北京神州绿盟信息安全科技股份有限公司 | 一种防御sql注入的方法、装置及系统 |
CN104537307A (zh) * | 2014-12-23 | 2015-04-22 | 北京奇虎科技有限公司 | 网站漏洞检测方法和系统 |
CN106355094A (zh) * | 2016-07-08 | 2017-01-25 | 耿童童 | 一种基于语法变换的sql注入攻击防御系统及防御方法 |
Also Published As
Publication number | Publication date |
---|---|
CN107122657A (zh) | 2017-09-01 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN107122657B (zh) | 一种防御sql注入攻击的数据库代理装置 | |
US11102223B2 (en) | Multi-host threat tracking | |
RU2668710C1 (ru) | Вычислительное устройство и способ для обнаружения вредоносных доменных имен в сетевом трафике | |
CN106357696B (zh) | 一种sql注入攻击检测方法及系统 | |
CN109495443B (zh) | 一种基于主机蜜罐对抗勒索软件攻击的方法和系统 | |
CN100448203C (zh) | 用于识别和防止恶意入侵的系统和方法 | |
US9495539B2 (en) | Method and system for protection against information stealing software | |
US9130986B2 (en) | Method and system for protection against information stealing software | |
US20120324575A1 (en) | System, Method, Program, and Recording Medium for Detecting and Blocking Unwanted Programs in Real Time Based on Process Behavior Analysis and Recording Medium for Storing Program | |
US20040064737A1 (en) | Hash-based systems and methods for detecting and preventing transmission of polymorphic network worms and viruses | |
WO2018099206A1 (zh) | 一种apt检测方法、系统及装置 | |
Kaur et al. | Automatic attack signature generation systems: A review | |
CN106549980A (zh) | 一种恶意c&c服务器确定方法及装置 | |
CN106470214A (zh) | 攻击检测方法和装置 | |
CA2718594A1 (en) | Method and system for protection against information stealing software | |
Almutairi et al. | Innovative signature based intrusion detection system: Parallel processing and minimized database | |
CN101901232A (zh) | 用于处理网页数据的方法和装置 | |
CN107770125A (zh) | 一种网络安全应急响应方法及应急响应平台 | |
CN109409113A (zh) | 一种电网数据安全防护方法和分布式电网数据安全防护系统 | |
CN113596044A (zh) | 一种网络防护方法、装置、电子设备及存储介质 | |
KR20050024571A (ko) | 하드웨어기반의 패턴매칭을 이용한 웜 차단 방법 및 장치 | |
Ruzhi et al. | A database security gateway to the detection of SQL attacks | |
CN104951711B (zh) | 一种保护web应用安全的网站结构拟态方法 | |
Jin et al. | Mitigating HTTP GET Flooding attacks through modified NetFPGA reference router | |
Das et al. | A web intrusion detection mechanism based on feature based data clustering |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20171019 Address after: 201112, 5 building, 3A building, 1588 union airways, Shanghai, Minhang District Applicant after: Shanghai RedNeurons Information Technology Co., Ltd. Applicant after: National Digital Switch System Engineering Technology Research Center Address before: 201112, 5 building, 3A building, 1588 union airways, Shanghai, Minhang District Applicant before: Shanghai RedNeurons Information Technology Co., Ltd. |
|
CB03 | Change of inventor or designer information | ||
CB03 | Change of inventor or designer information |
Inventor after: Zhang Zheng Inventor after: Luo Xingguo Inventor after: Wu Jiangxing Inventor after: Su Kunlun Inventor after: Ma Bolin Inventor after: Pang Jianmin Inventor after: Xie Guangwei Inventor before: Zhang Zheng Inventor before: Luo Xingguo Inventor before: Wu Jiangxing Inventor before: Su Kunlun Inventor before: Ma Bailin Inventor before: Pang Jianmin Inventor before: Xie Guangwei |
|
GR01 | Patent grant | ||
GR01 | Patent grant |