A survey on SQL injection attacks, detection and prevention techniques – a tertiary study


Abstract:

This paper presents a tertiary systematic literature review of SQL injection attacks based on previous secondary systematic literature reviews and systematic mappings. We identify the main observations (what we know) and challenges (what we do not know) on SQL injection attacks. We perform this tertiary review using six scientific databases. Based on a rigorous search process, we consider in our study 11 secondary studies published in the last decade. We define six research questions that help us determine the current state of the art in SQL injection attacks. We organise the main observations and challenges into definitions, most common research topics related to SQL injection attacks, detection and prevention techniques, and limitations of the studies. Finally, we identify open issues that could guide future research work.

Año de publicación:

2022

Keywords:

  • SQL injection detection techniques
  • SQLIA
  • SQL injection attacks
  • SQL injection prevention techniques

Fuente:

scopusscopus

Tipo de documento:

Article

Estado:

Acceso restringido

Áreas de conocimiento:

  • Base de datos
  • Ciencias de la computación

Áreas temáticas:

  • Ciencias de la computación