论文标题

解决横向注射攻击的安全设计模式方法

A Secure Design Pattern Approach Toward Tackling Lateral-Injection Attacks

论文作者

Biringa, Chidera, Kul, Gökhan

论文摘要

通常在软件开发的设计阶段引入了为对抗性漏洞创造攻击表面的软件弱点,例如侧向SQL注入(LSQLI)攻击。安全设计模式有时用于应对这些弱点。但是,由于基于侧向攻击的隐秘性质,采用传统的安全模式来应对这些威胁是不够的。因此,我们提出了SEAL,这是一种安全的设计,可以推断建筑,设计和实施抽象水平,以委派解决LSQLI攻击的安全策略。我们评估了使用案例研究软件的密封件,在该软件中,我们承担了对手的作用,并注入了几个攻击向量,这些攻击向量损害了其数据库的机密性和完整性。我们对密封的评估证明了其解决LSQLI攻击的能力。

Software weaknesses that create attack surfaces for adversarial exploits, such as lateral SQL injection (LSQLi) attacks, are usually introduced during the design phase of software development. Security design patterns are sometimes applied to tackle these weaknesses. However, due to the stealthy nature of lateral-based attacks, employing traditional security patterns to address these threats is insufficient. Hence, we present SEAL, a secure design that extrapolates architectural, design, and implementation abstraction levels to delegate security strategies toward tackling LSQLi attacks. We evaluated SEAL using case study software, where we assumed the role of an adversary and injected several attack vectors tasked with compromising the confidentiality and integrity of its database. Our evaluation of SEAL demonstrated its capacity to address LSQLi attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源