• ثبت نام
    • ورود به سامانه
    مشاهده مورد 
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • Journal of Radar and Optical Remote Sensing
    • Volume 4, Issue 3
    • مشاهده مورد
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • Journal of Radar and Optical Remote Sensing
    • Volume 4, Issue 3
    • مشاهده مورد
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    A Heuristic Model for SQL Injection Attacks Prevention in GIS Web Application

    (ندگان)پدیدآور
    Arasteh, Mohammad AliParsaei, Fahimeh
    Thumbnail
    دریافت مدرک مشاهده
    FullText
    اندازه فایل: 
    326.1کیلوبایت
    نوع فايل (MIME): 
    PDF
    نوع مدرک
    Text
    مقاله پژوهشی
    زبان مدرک
    English
    نمایش کامل رکورد
    چکیده
    By increasing the development of Geographical Information Systems (GIS) providing electronic map data exchange with internet and mobile applications, related problems such as keeping secure map information, safe transactions, and assured broadcast services are necessary. Every year millions of attacks on financial and data information will be caused a series of problems in the world. One of the most critical attacks on the application level is SQL injection into the Web database. This paper tried to present a model for preventing SQL injection into GIS applications, which leads to fetching and manipulating the map information and data from a database. It also provides solutions for IT managers to keep the GIS website secure. The model security steps were tested on one of the GIS portals of Iranian organizations. To evaluate the performance of the proposed model, the security of an Iranian web GIS was checked before and after the announcement of the instructions, and the test results of the vulnerability checking with Acunetix and DVWA. The result showed that the website was completely safe and the model's instructions for various stakeholders, including programmers, administrators, and GIS experts can significantly prevent this attack.
    کلید واژگان
    SQL Injection
    Web GIS Application-Level Vulnerabilities
    Authentication and Authorization
    Data Integrity
    Application Security Scanner

    شماره نشریه
    3
    تاریخ نشر
    2021-09-01
    1400-06-10
    ناشر
    Islamic Azad University, Yazd Branch
    دانشگاه آزاد اسلامی واحد یزد
    سازمان پدید آورنده
    Head of GIS Group, Yazd Water and Wastewater Company, Ph.D. Department of Information Technology, University of Qom, Iran
    Regulatory Center of the Iranian National Taz Administration (INTA), Tehran, Ph.D. Candidate, Department of Cognitive Neuroscience, University of Tabriz, Iran

    URI
    https://jrors.yazd.iau.ir/article_692525.html
    https://iranjournals.nlai.ir/handle/123456789/953725

    مرور

    همه جای سامانهپایگاه‌ها و مجموعه‌ها بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌هااین مجموعه بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌ها

    حساب من

    ورود به سامانهثبت نام

    آمار

    مشاهده آمار استفاده

    تازه ترین ها

    تازه ترین مدارک
    © کليه حقوق اين سامانه برای سازمان اسناد و کتابخانه ملی ایران محفوظ است
    تماس با ما | ارسال بازخورد
    قدرت یافته توسطسیناوب