{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T21:02:23Z","timestamp":1785790943054,"version":"3.56.0"},"reference-count":58,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,1,11]],"date-time":"2017-01-11T00:00:00Z","timestamp":1484092800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100002183","name":"Department of Electronics and Information Technology, Ministry of Communications and Information Technology (IN)","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2018,2]]},"DOI":"10.1007\/s10207-016-0359-4","type":"journal-article","created":{"date-parts":[[2017,1,11]],"date-time":"2017-01-11T10:14:35Z","timestamp":1484129675000},"page":"105-120","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Black-box detection of XQuery injection and parameter tampering vulnerabilities in web applications"],"prefix":"10.1007","volume":"17","author":[{"given":"G.","family":"Deepa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"P. Santhi","family":"Thilagam","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Furqan Ahmed","family":"Khan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amit","family":"Praseed","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alwyn R.","family":"Pais","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nushafreen","family":"Palsetia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,1,11]]},"reference":[{"key":"359_CR1","unstructured":"Symantec Corporation: Symantec internet security threat report: vol. 19. Symantec Corporation. http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/other_resources\/b-istr_main_report_v19_21291018.en-us (2014)"},{"key":"359_CR2","unstructured":"Foundation, O.: Top 10 2013-top 10. https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10 (2013)"},{"key":"359_CR3","unstructured":"CWE\/SANS top 25 most dangerous software errors. http:\/\/www.sans.org\/top25-software-errors\/ (2011)"},{"key":"359_CR4","unstructured":"Gordeychik, S.: Web application security statistics. The Web Application Security Consortium. http:\/\/projects.webappsec.org\/w\/page\/13246989\/WebApplicationSecurityStatistics (2008)"},{"key":"359_CR5","doi-asserted-by":"crossref","unstructured":"Bisht, P., Hinrichs, T., Skrupsky, N., Bobrowicz, R., Venkatakrishnan, V.N.: Notamper: Automatic blackbox detection of parameter tampering opportunities in web applications. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS \u201910, pp. 607\u2013618. ACM, New York (2010)","DOI":"10.1145\/1866307.1866375"},{"key":"359_CR6","doi-asserted-by":"crossref","unstructured":"Bisht, P., Hinrichs, T., Skrupsky, N., Venkatakrishnan, V.N.: Waptec: Whitebox analysis of web applications for parameter tampering exploit construction. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, CCS \u201911, pp. 575\u2013586. ACM, New York (2011)","DOI":"10.1145\/2046707.2046774"},{"key":"359_CR7","doi-asserted-by":"crossref","unstructured":"Skrupsky, N., Bisht, P., Hinrichs, T., Venkatakrishnan, V.N., Zuck, L.: Tamperproof: A server-agnostic defense for parameter tampering attacks on web applications. In: Proceedings of the Third ACM Conference on Data and Application Security and Privacy, CODASPY \u201913, pp. 129\u2013140. ACM, New York (2013)","DOI":"10.1145\/2435349.2435365"},{"key":"359_CR8","volume-title":"XML Data Management: Native XML and XML Enabled DataBase Systems","author":"A Chaudhri","year":"2003","unstructured":"Chaudhri, A., Zicari, R., Rashid, A.: XML Data Management: Native XML and XML Enabled DataBase Systems. Addison-Wesley Longman Publishing Co. Inc, Boston (2003)"},{"key":"359_CR9","doi-asserted-by":"publisher","unstructured":"Liu, Z.H., Murthy, R.: A decade of XML data management: An industrial experience report from oracle. In: IEEE 25th International Conference on Data Engineering, 2009. ICDE \u201909, pp. 1351\u20131362 (2009). doi: 10.1109\/ICDE.2009.18","DOI":"10.1109\/ICDE.2009.18"},{"key":"359_CR10","first-page":"181","volume":"30","author":"G Pavlovic-Lazetic","year":"2007","unstructured":"Pavlovic-Lazetic, G.: Native XML databases vs. relational databases in dealing with XML documents. Kragujevac J. Math. 30, 181\u2013199 (2007)","journal-title":"Kragujevac J. Math."},{"key":"359_CR11","unstructured":"Staken, K.: Introduction to native XML databases. http:\/\/www.xml.com\/pub\/a\/2001\/10\/31\/nativexmldb.html (2001)"},{"key":"359_CR12","unstructured":"Foundation, O.: Testing for XML injection. https:\/\/www.owasp.org\/index.php\/Testing_for_XML_Injection_OTG-INPVAL-008 (2014)"},{"key":"359_CR13","doi-asserted-by":"publisher","unstructured":"Palsetia, N., Deepa, G., Khan, F.A., Thilagam, P.S., Pais, A.R.: Securing native XML database-driven web applications from XQuery injection vulnerabilities. J. Syst. Softw.122, 93\u2013109 (2016). doi: 10.1016\/j.jss.2016.08.094 . http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0164121216301571","DOI":"10.1016\/j.jss.2016.08.094"},{"key":"359_CR14","unstructured":"Halfond, W., Viegas, J., Orso, A.: A classification of SQL-injection attacks and countermeasures. In: Proceedings of the IEEE International Symposium on Secure Software Engineering, pp. 65\u201381 (2006)"},{"key":"359_CR15","unstructured":"WASC: XQuery injection. http:\/\/projects.webappsec.org\/w\/page\/13247006\/XQueryInjection (2009)"},{"key":"359_CR16","doi-asserted-by":"crossref","unstructured":"Huang, Y.W., Yu, F., Hang, C., Tsai, C.H., Lee, D.T., Kuo, S.Y.: Securing web application code by static analysis and runtime protection. In: Proceedings of the 13th International Conference on World Wide Web, pp. 40\u201352. ACM (2004)","DOI":"10.1145\/988672.988679"},{"key":"359_CR17","doi-asserted-by":"crossref","unstructured":"Halfond, W.G., Orso, A.: Amnesia: analysis and monitoring for neutralizing SQL-injection attacks. In: Proceedings of the 20th IEEE\/ACM International Conference on Automated Software Engineering, pp. 174\u2013183. ACM (2005)","DOI":"10.1145\/1101908.1101935"},{"key":"359_CR18","doi-asserted-by":"crossref","unstructured":"Buehrer, G., Weide, B.W., Sivilotti, P.A.: Using parse tree validation to prevent SQL injection attacks. In: Proceedings of the 5th International Workshop on Software Engineering and Middleware, pp. 106\u2013113. ACM (2005)","DOI":"10.1145\/1108473.1108496"},{"issue":"5","key":"359_CR19","doi-asserted-by":"crossref","first-page":"739","DOI":"10.1016\/j.comnet.2005.01.003","volume":"48","author":"YW Huang","year":"2005","unstructured":"Huang, Y.W., Tsai, C.H., Lin, T.P., Huang, S.K., Lee, D., Kuo, S.Y.: A testing framework for web application security assessment. Comput. Netw. 48(5), 739\u2013761 (2005). Web Security","journal-title":"Comput. Netw."},{"key":"359_CR20","doi-asserted-by":"crossref","unstructured":"Su, Z., Wassermann, G.: The essence of command injection attacks in web applications. In: Conference Record of the 33rd ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, POPL \u201906, pp. 372\u2013382. ACM, New York (2006)","DOI":"10.1145\/1111037.1111070"},{"key":"359_CR21","first-page":"179","volume":"6","author":"Y Xie","year":"2006","unstructured":"Xie, Y., Aiken, A.: Static detection of security vulnerabilities in scripting languages. USENIX Secur. 6, 179\u2013192 (2006)","journal-title":"USENIX Secur."},{"key":"359_CR22","doi-asserted-by":"crossref","unstructured":"Kosuga, Y., Kernel, K., Hanaoka, M., Hishiyama, M., Takahama, Y.: Sania: Syntactic and semantic analysis for automated testing against SQL injection. In: Twenty-Third Annual Computer Security Applications Conference, ACSAC 2007, pp. 107\u2013117. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.20"},{"key":"359_CR23","doi-asserted-by":"crossref","unstructured":"Wassermann, G., Su, Z.: Sound and precise analysis of web applications for injection vulnerabilities. In: Proceedings of the 2007 ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201907, pp. 32\u201341. ACM, New York (2007)","DOI":"10.1145\/1250734.1250739"},{"key":"359_CR24","doi-asserted-by":"crossref","unstructured":"Liu, A., Yuan, Y., Wijesekera, D., Stavrou, A.: SQLProb: A proxy-based architecture towards preventing SQL injection attacks. In: Proceedings of the 2009 ACM Symposium on Applied Computing, SAC \u201909, pp. 2054\u20132061. ACM, New York (2009)","DOI":"10.1145\/1529282.1529737"},{"key":"359_CR25","doi-asserted-by":"crossref","unstructured":"Bisht, P., Madhusudan, P., Venkatakrishnan, V.: Candid: Dynamic candidate evaluations for automatic prevention of SQL injection attacks. ACM Trans. Inf. Syst. Secur. (TISSEC) 13(2), 14 (2010)","DOI":"10.1145\/1698750.1698754"},{"key":"359_CR26","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1016\/j.cose.2014.04.007","volume":"44","author":"YS Jang","year":"2014","unstructured":"Jang, Y.S., Choi, J.Y.: Detecting SQL injection attacks using query result size. Comput. Secur. 44, 104\u2013118 (2014)","journal-title":"Comput. Secur."},{"issue":"2","key":"359_CR27","doi-asserted-by":"crossref","first-page":"250","DOI":"10.1016\/j.jss.2010.09.020","volume":"84","author":"H Shahriar","year":"2011","unstructured":"Shahriar, H., Zulkernine, M.: Taxonomy and classification of automatic monitoring of program security vulnerability exploitations. J. Syst. Softw. 84(2), 250\u2013269 (2011)","journal-title":"J. Syst. Softw."},{"issue":"3","key":"359_CR28","doi-asserted-by":"crossref","first-page":"11:1","DOI":"10.1145\/2187671.2187673","volume":"44","author":"H Shahriar","year":"2012","unstructured":"Shahriar, H., Zulkernine, M.: Mitigating program security vulnerabilities: Approaches and challenges. ACM Comput. Surv. 44(3), 11:1\u201311:46 (2012)","journal-title":"ACM Comput. Surv."},{"issue":"4","key":"359_CR29","first-page":"54:1","volume":"46","author":"X Li","year":"2014","unstructured":"Li, X., Xue, Y.: A survey on server-side approaches to securing web applications. ACM Comput. Surv. 46(4), 54:1\u201354:29 (2014)","journal-title":"ACM Comput. Surv."},{"key":"359_CR30","doi-asserted-by":"publisher","unstructured":"Deepa, G., Thilagam, P.S.: Securing web applications from injection and logic vulnerabilities: approaches and challenges. Inf. Softw. Technol. 74, 160\u2013180 (2016). doi: 10.1016\/j.infsof.2016.02.005 . http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0950584916300234","DOI":"10.1016\/j.infsof.2016.02.005"},{"key":"359_CR31","doi-asserted-by":"crossref","unstructured":"Chandrashekhar, R., Mardithaya, M., Thilagam, P.S., Saha, D.: SQL injection attack mechanisms and prevention techniques. In: Advanced Computing, Networking and Security, pp. 524\u2013533. Springer, Berlin (2012)","DOI":"10.1007\/978-3-642-29280-4_61"},{"key":"359_CR32","doi-asserted-by":"crossref","unstructured":"Bravenboer, M., Dolstra, E., Visser, E.: Preventing injection attacks with syntax embeddings. In: Proceedings of the 6th International Conference on Generative Programming and Component Engineering, pp. 3\u201312. ACM (2007)","DOI":"10.1145\/1289971.1289975"},{"key":"359_CR33","unstructured":"OWASP: XPath injection. https:\/\/www.owasp.org\/index.php\/XPATH_Injection (2015)"},{"key":"359_CR34","unstructured":"Truelove, J., Svoboda, D.: Ids09-j. prevent XPath injection. https:\/\/www.securecoding.cert.org\/confluence\/pages\/viewpage.action?pageId=61407250 (2011)"},{"key":"359_CR35","unstructured":"Mitropoulos, D., Karakoidas, V., Spinellis, D.: Fortifying applications against XPath injection attacks. In: Proceedings of the 4th Mediterranean Conference on Information Systems (MCIS\u201909), Athens, Greece, pp. 1169\u20131179 (2009)"},{"issue":"3","key":"359_CR36","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1108\/09685221111153555","volume":"19","author":"D Mitropoulos","year":"2011","unstructured":"Mitropoulos, D., Karakoidas, V., Louridas, P., Spinellis, D.: Countering code injection attacks: a unified approach. Inf. Manag. Comput. Secur. 19(3), 177\u2013194 (2011)","journal-title":"Inf. Manag. Comput. Secur."},{"key":"359_CR37","doi-asserted-by":"publisher","unstructured":"Rosa, T.M., Santin, A.O., Malucelli, A.: Mitigating XML injection 0-day attacks through strategy-based detection systems. IEEE Secur. Priv. 11(4), 46\u201353 (2013). doi: 10.1109\/MSP.2012.83","DOI":"10.1109\/MSP.2012.83"},{"key":"359_CR38","doi-asserted-by":"crossref","unstructured":"Antunes, N., Vieira, M.: Enhancing penetration testing with attack signatures and interface monitoring for the detection of injection vulnerabilities in web services. In: IEEE International Conference on Services Computing (SCC), pp. 104\u2013111. IEEE (2011)","DOI":"10.1109\/SCC.2011.67"},{"key":"359_CR39","doi-asserted-by":"crossref","unstructured":"Laranjeiro, N., Vieira, M., Madeira, H.: Protecting database centric web services against SQL\/XPath injection attacks. In: Database and Expert Systems Applications, pp. 271\u2013278. Springer, Berlin (2009)","DOI":"10.1007\/978-3-642-03573-9_22"},{"key":"359_CR40","doi-asserted-by":"publisher","unstructured":"Antunes, N., Laranjeiro, N., Vieira, M., Madeira, H.: Effective detection of SQL\/XPath injection vulnerabilities in web services. In: IEEE International Conference on Services Computing, pp. 260\u2013267. IEEE (2009). doi: 10.1109\/SCC.2009.23","DOI":"10.1109\/SCC.2009.23"},{"key":"359_CR41","unstructured":"Asmawi, A., Affendey, L.S., Udzir, N.I., Mahmod, R.: Model-based system architecture for preventing XPath injection in database-centric web services environment. In: 7th International Computing and Convergence Technology (ICCCT), pp. 621\u2013625. IEEE (2012)"},{"key":"359_CR42","unstructured":"Forbes, T.: Exploiting XPath injection vulnerabilities with xcat. http:\/\/tomforb.es\/exploiting-xpath-injection-vulnerabilities-with-xcat-1 (2014)"},{"key":"359_CR43","unstructured":"WebCruiser: Webcruiser-web vulnerability scanner. http:\/\/www.ehacking.net\/2011\/07\/webcruiser-web-vulnerability-scanner.html (2011)"},{"key":"359_CR44","unstructured":"XMLMao: XMLMao. https:\/\/www.soldierx.com\/tools\/XMLmao (2012)"},{"key":"359_CR45","unstructured":"Acunetix: Acunetix. http:\/\/www.acunetix.com\/ (2014)"},{"key":"359_CR46","unstructured":"Laskos, T.: Web application vulnerability scanning framework. http:\/\/www.arachni-scanner.com\/"},{"key":"359_CR47","unstructured":"Wapiti: The web-application vulnerability scanner. http:\/\/wapiti.sourceforge.net\/ (2013)"},{"key":"359_CR48","unstructured":"Riancho, A.: w3af. http:\/\/w3af.sourceforge.net (2011)"},{"key":"359_CR49","unstructured":"van\u00a0der Loo, F.: Comparison of penetration testing tools for web applications. Ph.D. thesis, Master thesis, Radboud University Nijmegen, 2011. http:\/\/www.ru.nl\/publish\/pages\/578936\/frank_van_der_loo_scriptie.pdf (2011)"},{"key":"359_CR50","doi-asserted-by":"crossref","unstructured":"Mouelhi, T., Le\u00a0Traon, Y., Abgrall, E., Baudry, B., Gombault, S.: Tailored shielding and bypass testing of web applications. In: 2011 IEEE Fourth International Conference on Software Testing, Verification and Validation (ICST), pp. 210\u2013219 (2011)","DOI":"10.1109\/ICST.2011.56"},{"key":"359_CR51","doi-asserted-by":"crossref","unstructured":"Alkhalaf, M., Choudhary, S.R., Fazzini, M., Bultan, T., Orso, A., Kruegel, C.: Viewpoints: Differential string analysis for discovering client- and server-side input validation inconsistencies. In: Proceedings of the 2012 International Symposium on Software Testing and Analysis, ISSTA 2012, pp. 56\u201366. ACM, New York (2012)","DOI":"10.1145\/2338965.2336760"},{"key":"359_CR52","unstructured":"Balduzzi, M., Gimenez, C.T., Balzarotti, D., Kirda, E.: Automated discovery of parameter pollution vulnerabilities in web applications. In: Proceedings of the 18th Network and Distributed System Security Symposium, NDSS\u201911. San Diego (2011)"},{"key":"359_CR53","unstructured":"Redis: Redis. http:\/\/redis.io\/"},{"key":"359_CR54","unstructured":"WebSPHINX: WebSPHINX: A personal, customizable web crawler. http:\/\/www.cs.cmu.edu\/~rcm\/websphinx\/ (2002)"},{"key":"359_CR55","unstructured":"JSpider: Jspider. http:\/\/j-spider.sourceforge.net\/ (2013)"},{"key":"359_CR56","unstructured":"Django: Django-the web framework for perfectionists with deadlines. https:\/\/www.djangoproject.com\/"},{"key":"359_CR57","unstructured":"PostgreSQL: PostgreSQL-the world\u2019s most advanced open source database. http:\/\/www.postgresql.org\/"},{"key":"359_CR58","unstructured":"BaseX: Basex-the XML database. http:\/\/basex.org\/"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-016-0359-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0359-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0359-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,17]],"date-time":"2019-09-17T07:45:07Z","timestamp":1568706307000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-016-0359-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,1,11]]},"references-count":58,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,2]]}},"alternative-id":["359"],"URL":"https:\/\/doi.org\/10.1007\/s10207-016-0359-4","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1,11]]}}}