Towards full protection of web applications based on Aspect Oriented Programming

Article ID

Z5SYF

Towards full protection of web applications based on Aspect Oriented Programming

Dr. Elinda Kajo Mece
Dr. Elinda Kajo Mece
Lorena Kodra
Lorena Kodra Polytechnic University of Tirana
DOI

Abstract

Web application security is a critical issue. Security concerns are often scattered through different parts of the system. Aspect oriented programming is a programming paradigm that provides explicit mechanisms to modularize these concerns. In this paper we present a technique for detecting and preventing common attacks in web applications like Cross Site Scripting (XSS) and SQL Injection using an aspect oriented approach by analyzing and validating user input strings. We use an aspect to capture input strings and compare them to predefined patterns. The intrusion detection aspect is implemented in AspectJ and is woven into the target system. The resulting system has the ability to detect malicious user input and prevent SQL Injection and Cross Site Scripting. We present an experimental evaluation by applying it to an insecure web application. The results of our tests show that our technique was able to detect all the attempted attacks without generating any false positives.

Towards full protection of web applications based on Aspect Oriented Programming

Web application security is a critical issue. Security concerns are often scattered through different parts of the system. Aspect oriented programming is a programming paradigm that provides explicit mechanisms to modularize these concerns. In this paper we present a technique for detecting and preventing common attacks in web applications like Cross Site Scripting (XSS) and SQL Injection using an aspect oriented approach by analyzing and validating user input strings. We use an aspect to capture input strings and compare them to predefined patterns. The intrusion detection aspect is implemented in AspectJ and is woven into the target system. The resulting system has the ability to detect malicious user input and prevent SQL Injection and Cross Site Scripting. We present an experimental evaluation by applying it to an insecure web application. The results of our tests show that our technique was able to detect all the attempted attacks without generating any false positives.

Dr. Elinda Kajo Mece
Dr. Elinda Kajo Mece
Lorena Kodra
Lorena Kodra Polytechnic University of Tirana

No Figures found in article.

Dr.Elinda Kajo Mece. 1970. “. Unknown Journal GJCST Volume 12 (GJCST Volume 12 Issue 1): .

Download Citation

Journal Specifications
Classification
Not Found
Article Matrices
Total Views: 20855
Total Downloads: 11075
2026 Trends
Research Identity (RIN)
Related Research
Our website is actively being updated, and changes may occur frequently. Please clear your browser cache if needed. For feedback or error reporting, please email [email protected]

Request Access

Please fill out the form below to request access to this research paper. Your request will be reviewed by the editorial or author team.
X

Quote and Order Details

Contact Person

Invoice Address

Notes or Comments

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

High-quality academic research articles on global topics and journals.

Towards full protection of web applications based on Aspect Oriented Programming

Dr. Elinda Kajo Mece
Dr. Elinda Kajo Mece
Lorena Kodra
Lorena Kodra Polytechnic University of Tirana

Research Journals