Logo Lanfrica
  • Accueil
  • Atlas
  • Analyses
  • Documentation
  • Sign in

© 2026 Lanfrica. Tous droits réservés. Tous les droits d'auteur des ressources affichées sur le site Web Lanfrica appartiennent aux détenteurs de droits d'auteur d'origine, sauf indication contraire explicite.

A combined approach of fine Role-Based Access Control and dynamic/static parse tree comparison to mediate SQL Injection Attacks within a selected West African case system and context

Domaine:

digital infrastructure
Créateur:
Eva
Éditeur:
Dur
Hôte:
Business legacy systems, when migrated to the Web, often face increased chances of Structured Query Language (SQL) injection attacks; these attacks are compounded when this system lacks proper security mechanisms and security training for its staff. This study seeks to determine how the researcher’s new theory of amalgamating two established techniques for defence namely; fine-grained Role-Based Access Control (RBAC) and static/dynamic parse tree comparison; can be combined to form a single centralized defence in order to effectively mitigate SQL injection attacks in a web-based environment, using a selected recently migrated legacy system as an exemplar. This proposed defence first involves redefining existing RBAC security to a fine-grained RBAC to act as the first tier of defence. Those queries, legitimate or not, which successfully pass through the first tier are analysed by the second tier of defence that is designed to both do a static and dynamic parse tree analysis and comparison of the queries in order to identify legitimate queries from illegitimate queues. During the study, it was discovered that the basic RBAC in control system and the fine grained RBAC could only mitigate a fraction of the selected test cases and thereby generated a number of false positives but no false negatives. However, those false positives were successfully identified and mitigated by the second tier of static/dynamic parse tree comparison. As such the measurement of performance using precision, recall and f-measure were determined in three cases namely basic RBAC defence in control with 31% precision,100% recall and f-measure of 32%; Fine grained RBAC without dynamic parse tree comparism with 54% precision ,100% recall and fmeaure of 54% and hybrid defence of fine grained RBAC and dynamic parse tree comparism with 100 % precision with a 100 % recall and f-measure of 100% with the test cases used in a repeated experimentation. However extensive real-world testing might expose weaknesses not observed during experimentation and such is the recommendation of the study. This entire approach is centralized in a security aspect in order to easily incorporate it into vulnerable newly migrated legacy systems to the web which requires minimal training of security staff for deployment. The hybrid was then tested using a case sample system that represents the West African context of inadequate security mechanisms and poor staff training. Standard test cases were used to test each defence tier in the hybrid as well as the individual tiers. This testing detected and halted illegitimate SQL queues and demonstrated this aspect’s effectiveness and suitability for the West African context.

Visit

doi.org

Similaires

Campus Microgrids within the South African Context: A Case Study to Illustrate Unique Design, Control Challenges, and Hybrid Dispatch StrategiesSystem Drivers of Hypertension Control in Africa: A Beta Regression and Dynamic Factor Modeling ApproachStatic hedging of vanilla and exotic options in a South African contextA Study of Online Database Servers: The Case of SQL - Injection, How Evil that could be?Financial System and SMEs Access to Finance: A Market-Oriented ApproachStatic and dynamic performance assessment of a grid-connected solar photovoltaic system in a Nigerian 33/11 kV distribution network

Campus Microgrids within the South African Context: A Case Study to Illustrate Unique Design, Control Challenges, and Hybrid Dispatch Strategies

South African universities boast a remarkable solar photovoltaic (PV) resource as a primary renewabl

System Drivers of Hypertension Control in Africa: A Beta Regression and Dynamic Factor Modeling Approach

International audience Noncommunicable Disease (NCD) Risk Factor Collaboration suppli

Static hedging of vanilla and exotic options in a South African context

In this paper, we test the performance of a static hedging strategy for a long-dated European call o

A Study of Online Database Servers: The Case of SQL - Injection, How Evil that could be?

International audience SQL injection attack is one of the most serious security vulne

Financial System and SMEs Access to Finance: A Market-Oriented Approach

Abstract The study uses a market-oriented approach to investigate the relationsh

Static and dynamic performance assessment of a grid-connected solar photovoltaic system in a Nigerian 33/11 kV distribution network

In this study, we investigate the impact of a 2.5 MW grid-connected solar photovoltaic generation (S