A novel technique to prevent SQL injection and cross-site scripting attacks using Knuth-Morris-Pratt string match algorithm

dc.contributor.authorAbikoye Oluwakemi Christiana
dc.contributor.authorAbubakar Abdullahi
dc.contributor.authorDokoro Ahmed Haruna
dc.contributor.authorAkande Oluwatobi Noah
dc.contributor.authorKayode Aderonke Anthonia
dc.date.accessioned2025-08-08T12:06:37Z
dc.date.issued2020-08-08
dc.description.abstractStructured Query Language (SQL) injection and cross-site scripting remain a major threat to data-driven web applications. Instances where hackers obtain unrestricted access to back-end database of web applications so as to steal, edit, and destroy confidential data are increasing. Therefore, measures must be put in place to curtail the growing threats of SQL injection and XSS attacks. This study presents a technique for detecting and preventing these threats using Knuth-Morris-Pratt (KMP) string matching algorithm. The algorithm was used to match user’s input string with the stored pattern of the injection string in order to detect any malicious code. The implementation was carried out using PHP scripting language and Apache XAMPP Server. The security level of the technique was measured using different test cases of SQL injection, cross-site scripting (XSS), and encoded injection attacks. Results obtained revealed that the proposed technique was able to successfully detect and prevent the attacks, log the attack entry in the database, block the system using its mac address, and also generate a warning message. Therefore, the proposed technique proved to be more effective in detecting and preventing SQL injection and XSS attacks
dc.identifier.citationAbikoye Oluwakemi Christiana et al.(20202). A novel technique to prevent SQL injection and cross-site scripting attacks using Knuth-Morris-Pratt string match algorithm. EURASIP Journal on Information Security
dc.identifier.uridoi.org/10.1186/s13635-020-00113-y
dc.identifier.urihttps://repository.nileuniversity.edu.ng/handle/123456789/601
dc.language.isoen
dc.publisherSpringer Open
dc.subjectSQL injection
dc.subjectCross-site scripting
dc.subjectInformation security
dc.subjectWeb application vulnerability
dc.subjectKnuth-Morris-Pratt (KMP) string matching algorithm
dc.titleA novel technique to prevent SQL injection and cross-site scripting attacks using Knuth-Morris-Pratt string match algorithm
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
A novel technique to prevent SQL injection.pdf
Size:
3.06 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description: