loading
  • Login
  • Sign-Up

Research.Publish.Connect.

Paper

Authors: Francesco Di Tria ; Ezio Lefons and Filippo Tangorra

Affiliation: Università degli Studi di Bari Aldo Moro, Italy

ISBN: 978-989-758-167-0

Keyword(s): SQL Injection, Authentication, Authorization, Web Application, Architecture.

Related Ontology Subjects/Areas/Topics: Data and Application Security and Privacy ; Database Security ; Information and Systems Security

Abstract: In web applications, databases are generally used as data repositories, where a server-side program interacts with a Database Management System (DBMS), retrieves content, and dynamically generates web pages. This is known as a three-layer architecture, that is widely exposed to database threats. The attacks are usually performed through the injection of SQL code in the forms of the web applications, exploiting the dynamic construction of SQL statements. So, the database security relies on the quality of the code and the controls done by the web developer in the application level. In this paper, we present a solution for the improvement of security of databases accessed by web applications. The security is based on a user modelling approach that completely relies on the authorization mechanism of DBMSs.

PDF ImageFull Text

Download
Sign In Guest: Register as new SCITEPRESS user or Join INSTICC now for free.

Sign In SCITEPRESS user: please login.

Sign In INSTICC Members: please login. If not a member yet, Join INSTICC now for free.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 54.145.219.80. INSTICC members have higher download limits (free membership now)

In the current month:
Recent papers: 1 available of 1 total
2+ years older papers: 2 available of 2 total

Paper citation in several formats:
Di Tria F., Lefons E. and Tangorra F. (2016). Improving Database Security in Web-based Environments.In Proceedings of the 2nd International Conference on Information Systems Security and Privacy ISBN 978-989-758-167-0, pages 193-200. DOI: 10.5220/0005646901930200

@conference{icissp16,
author={Francesco Di Tria and Ezio Lefons and Filippo Tangorra},
title={Improving Database Security in Web-based Environments},
booktitle={Proceedings of the 2nd International Conference on Information Systems Security and Privacy },
year={2016},
pages={193-200},
doi={10.5220/0005646901930200},
isbn={978-989-758-167-0},
}

TY - CONF

JO - Proceedings of the 2nd International Conference on Information Systems Security and Privacy
TI - Improving Database Security in Web-based Environments
SN - 978-989-758-167-0
AU - Di Tria F.
AU - Lefons E.
AU - Tangorra F.
PY - 2016
SP - 193
EP - 200
DO - 10.5220/0005646901930200

Sorted by: Show papers

Note: The preferred Subjects/Areas/Topics, listed below for each paper, are those that match the selected paper topics and their ontology superclasses.
More...

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.

Show authors

Note: The preferred Subjects/Areas/Topics, listed below for each author, are those that more frequently used in the author's papers.
More...