University of Illinois Chicago
Browse

Ensuring Privacy in Legacy Web Applications through Multiple Relations Views

Download (262.5 kB)
thesis
posted on 2018-11-27, 00:00 authored by Pietro Di Marco
This thesis is focused on the protection of legacy Web Applications against information leakage as well as the defense against well known attacks such as some form of SQLInjection. Many legacy Web Applications are unsafe because security protection techniques such as input sanitization, quote saving, bound parameters were not implemented at the moment of creation. This work proposes a solution to this problem that requires minimal modification to the Web Application and no modifications to the database as it works between these two entities in an almost independent fashion. In particular the solution is a wrapper implemented in Java that works by intercepting the queries issued by the Web Application and modifying them according to the policies defined by the DBA. This thesis aims both to maximize the protection of legacy web applications as well as minimize the performance overhead introduced by the wrapper.

History

Advisor

Sistla, Prasad

Chair

Sistla, Prasad

Department

Computer Science

Degree Grantor

University of Illinois at Chicago

Degree Level

  • Masters

Committee Member

Grechanik, Mark Zanero, Stefano

Submitted date

August 2018

Issue date

2018-06-06

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC