A Static Analysis Framework For Detecting SQL Injection Vulnerabilities

Xiang Fu, Xin Lu, Boris Peltsverger, Chen Shi-jun, Kai Qian, Lixin Tao

Proceedings - International Computer Software & Applications Conference · 2007 · 145 citations · 12 references

Concepts

TL;DR

SQL injection attacks pose a major threat to web applications by enabling attackers to manipulate backend databases through crafted user input. The study proposes SAFELI, a static analysis framework to detect SQL injection vulnerabilities at compile time. SAFELI statically analyzes ASP.NET MSIL bytecode with symbolic execution and a hybrid constraint solver to identify user inputs that could breach security at SQL query hotspots. SAFELI shows potential to uncover more subtle SQL injection attacks than existing black‑box security tools.

Abstract

Recently SQL injection attack (SIA) has become a major threat to Web applications. Via carefully crafted user input, attackers can expose or manipulate the back-end database of a Web application. This paper proposes the construction and outlines the design of a static analysis framework (called SAFELI) for identifying SIA vulnerabilities at compile time. SAFELI statically inspects MSIL bytecode of an ASP.NET Web application, using symbolic execution. At each hotspot that submits SQL query, a hybrid constraint solver is used to find out the corresponding user input that could lead to breach of information security. Once completed, SAFELI has the future potential to discover more delicate SQL injection attacks than black-box Web security inspection tools.

References

12