01369nas a2200169 4500000000100000000000100001008004100002260001200043100002400055700002300079700001900102700001900121245008800140856007000228520085200298022004901150 2021 d c10/20211 aMohammed Nasereddin1 aAshaar ALKhamaiseh1 aMalik Qasaimeh1 aRaad Al-Qassas00aA systematic review of detection and prevention techniques of SQL injection attacks uhttps://www.tandfonline.com/doi/abs/10.1080/19393555.2021.19955373 a
SQL injection is a type of database-targeted attack for data-driven applications. It is performed by inserting malicious code in the SQL query to alter and modify its meaning, enabling the attacker to retrieve sensitive data or to access the database. Many techniques have been improved and proposed to detect and mitigate these types of attacks. This paper provides a systematic review for a pool of 60 papers on web applications’ SQL injection detection methods. The pool was selected using a developed searching and filtering methodology for the existing literature based on scholar databases (IEEE, ScienceDirect, and Springer) with the aim to provide specific answering for several research questions in the area of SQL injection detection. This provides a basis for the design and use of effective SQL injection detection methods.
aPrint ISSN: 1939-3555 Online ISSN: 1939-3547