Scalable Detection of SQL Injection in Cyber Physical Systems

  • Michael Silva UECE
  • Silvio Ribeiro UECE
  • Vanessa Carvalho UECE
  • Francisco Cardoso UECE
  • Rafael Lopes Gomes UECE

Resumo


Cyber Physical Systems generate a significant volume of heterogeneous data often stored in relational databases. These databases are susceptible to various threats, including SQL Injection (SQLi) attacks. Consequently, there is a need for security solutions that are not only efficient in detection, but also meet the processing time requirements of detection. In this context, this article introduces a solution for SQLi Scalable Threat Detection (S-SQLi) based on Regular Expressions (RegEx). This solution acts as an initial filtering service, protecting against SQLi threats by addressing response time and scalability concerns. The experiments using a real dataset suggest that S-SQLi offers adequate detection efficiency for SQLi threats while addressing the scalability needs of CPSs.
Palavras-chave: Software defined networks, IOT, Wireless networks, real-time communication
Publicado
16/10/2023
SILVA, Michael; RIBEIRO, Silvio; CARVALHO, Vanessa; CARDOSO, Francisco; GOMES, Rafael Lopes. Scalable Detection of SQL Injection in Cyber Physical Systems. In: WORKSHOP ON SECURITY, PRIVACY AND RELIABILITY ON WIRELESS SENSING NETWORKS (WSENSING), 3. , 2023, La Paz/Bolívia. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2023 . p. 220–225.