计算机科学 ›› 2012, Vol. 39 ›› Issue (Z11): 9-13.

• 综述 • 上一篇    下一篇

sQL服务器注入攻击的主动防御技术研究

王文明 李海炜   

  1. (北京理工大学计算机学院 北京 100081)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Research of the Active Defense Technology for the SQI. Server Injection Attack

  • Online:2018-11-16 Published:2018-11-16

摘要: 针对MSSQI注入攻击,研究认为只有主动防御,方能变被动为主动,进而从根本上使SQI、服务器达到真正 意义上的安全。设计开发了一套主动防御软件,它通过远程线程注入技术,挂钩SQL Server进程的API函数,实现主 动防御策略。主动防御程序拦截到SQL Server的进程创建行为后,将进程创建参数发送到蜜罐主机去执行,并将蜜 罐主机中的执行结果作为SQI_ Scrvcr的执行结果。结合第三方的计算机监控软件,对蜜罐主机进行监控,可以收集 入侵者的信息,进而追踪入侵者。本软件还具备端口映射功能,可以将真实主机的端口映射到蜜罐主机上,从而增强 蜜罐主机的欺骗性。当检测到恶意攻击时,系统提供了短信警报和邮件警报两种警报方式,以保证在第一时间通知系 统管理员。

关键词: SQI,主动防御,注入,蜜罐

Abstract: In view of MSSQL injection attack,the research here thinks that only the active defense can become passive to be active, and then fundamentally lets SQI_ server achieve a real sense of security. hhis paper designed and developed a set of active defense software, which realizes active defense by hooking the APIs of SQL Server process through re- mote thread injection technology. After the active defense software intercepts the creation of process by SQI_ Server, it sends the process creation parameters to the honey pot for execution, and replaces the result of SQL Server with the re- ply of the honey pot. With third-party computer monitoring software, monitoring the honey pot, the system can gather the information of the attackers,and track them. The software also features port mapping. Port of the real host can be mapped to the honey pot, thereby to enhance the honey pot deceptive. When malicious attack is detected, the system provides two ways, SMS alert and F-mail alert, to inform your system administrator as soon as possible.

Key words: SQL,Active defense,Injection,Honey pot

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!