Poor Coding Leads to DoS Attack and Security Issues in Web Applications for Sensors

Author:

Jalbani Khuda Bux1ORCID,Yousaf Muhammad1ORCID,Sarfraz Muhammad Shahzad2,Jamili Oskouei Rozita3ORCID,Hussain Akhtar4ORCID,Memon Zojan5ORCID

Affiliation:

1. Riphah Institute of Systems Engineering, Riphah International University, Islamabad 44000, Pakistan

2. Department of Computer Science, National University of Computer and Emerging Sciences, Islamabad, Pakistan

3. Department of Computer Science and Information Technology, Islamic Azad University, Mahdishahr Branch, Mahdishahr, Iran

4. Department of Information Technology, Quaid-E-Awam University of Engineering, Science and Technology, Nawabshah 67450, Pakistan

5. Department of Information Technology, University of Sufism and Modern Sciences, Bhitshah 70140, Pakistan

Abstract

As the SQL injection attack is still at the top of the list at Open Web Application Security Project (OWASP) for more than one decade, this type of attack created too many types of issues for a web application, sensors, or any similar type of applications, such as leakage of user private data and organization intellectual property, or may cause Distributed Denial of Service (DDoS) attacks. This paper focused on the poor coding or invalidated input field which is a big cause of services unavailability for web applications. Secondly, it focused on the selection of program created issues for the WebSocket connections between sensors and the webserver. The number of users is growing to use web applications and mobile apps. These web applications or mobile apps are used for different purposes such as tracking vehicles, banking services, online stores for shopping, taxi booking, logistics, education, monitoring user activities, collecting data, or sending any instructions to sensors, and social websites. Web applications are easy to develop with less time and at a low cost. Due to that, business community or individual service provider’s first choice is to have a website and mobile app. So everyone is trying to provide 24/7 services to its users without any downtime. But there are some critical issues of web application design and development. These problems are leading to too many security loopholes for web servers, web applications, and its user’s privacy. Because of poor coding and validation of input fields, these web applications are vulnerable to SQL Injection and other security problems. Instead of using the latest third-party frameworks, language for website development, and version database server, another factor to disturb the services of a web server may be the socket programming for sensors at the production level. These sensors are installed in vehicles to track or use them for booking mobile apps.

Publisher

Hindawi Limited

Subject

Computer Networks and Communications,Information Systems

Reference32 articles.

1. A classification of SQL-injection attacks and countermeasures;W. G. Halfond

2. SQL injection detection and prevention tools assessment;A. Tajpour

3. A demand-side viewpoint to software vulnerabilities in WordPress plugins;J. Ruohonen

4. Analysis and design of security in the internet of things;C. Tian

5. Smart Home-based IoT for Real-time and Secure Remote Health Monitoring of Triage and Priority System using Body Sensors: Multi-driven Systematic Review

Cited by 4 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3