{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T03:50:32Z","timestamp":1760586632077,"version":"3.40.3"},"reference-count":18,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2012,9,26]],"date-time":"2012-09-26T00:00:00Z","timestamp":1348617600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int J Syst Assur Eng Manag"],"published-print":{"date-parts":[[2012,12]]},"DOI":"10.1007\/s13198-012-0125-6","type":"journal-article","created":{"date-parts":[[2012,9,25]],"date-time":"2012-09-25T03:53:06Z","timestamp":1348545186000},"page":"343-351","source":"Crossref","is-referenced-by-count":23,"title":["Integrated approach to prevent SQL injection attack and reflected cross site scripting attack"],"prefix":"10.1007","volume":"3","author":[{"given":"Pankaj","family":"Sharma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rahul","family":"Johari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. S.","family":"Sarma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,9,26]]},"reference":[{"key":"125_CR18","unstructured":"Clinton L (undated) Cyber-insurance metrics and impact on cyber-security. http:\/\/www.whitehouse.gov\/files\/documents\/cyber\/ISA-Cyber-InsuranceMetricandImpactonCyber-Security.pdf . Accessed Aug 2012"},{"key":"125_CR1","unstructured":"Common Weakness Enumeration (2012) CWE-89: improper neutralization of special elements used in an SQL command (\u2018SQL injection\u2019). http:\/\/cwe.mitre.org\/data\/definitions\/89.html . Accessed 13 Jan 2012"},{"key":"125_CR2","unstructured":"Common Weakness Enumeration (2012) CWE-79: improper neutralization of input during web page generation (\u2018cross-site scripting\u2019). http:\/\/cwe.mitre.org\/data\/definitions\/79.html . Accessed 13 Jan 2012"},{"key":"125_CR3","unstructured":"ENISA (2012) Incentives and barriers of the cyber insurance market in Europe June 2012. European Network and Information Security Agency (ENISA), Heraklion. http:\/\/www.enisa.europa.eu . Accessed 5 July 2012"},{"key":"125_CR4","unstructured":"Gould C, Su Z, Devanbu P (2044) Java database connectivity (JDBC) checker: a static analysis tool for SQL\/JDBC applications. In: Proceedings of the 26th international conference on software engineering (ICSE 2004) formal demos, p 697\u2013698. ICSE, Minneapolis"},{"key":"125_CR5","doi-asserted-by":"crossref","unstructured":"Halfond W, Orso A (2005) AMNESIA: analysis and monitoring for neutralizing SQL injection attacks. In: Proceedings on 20th IEEE and ACM international conference automated software engineering, p 174\u2013183. ACM, New York","DOI":"10.1145\/1101908.1101935"},{"key":"125_CR6","doi-asserted-by":"crossref","unstructured":"Jeom-Goo K (2011) Injection attack detection using the removal of SQL query attribute values. In: Information science and applications (ICISA), international conference, p 1\u20137. Department of Computer Science, Namseoul University, Cheonan, 26\u201329 April 2011","DOI":"10.1109\/ICISA.2011.5772411"},{"key":"125_CR7","doi-asserted-by":"crossref","unstructured":"Junjin M (2009) An approach for SQL injection vulnerability detection. In: Proceedings of the 6th international conference on information technology: new generations, p 1411\u20131414. IEEE, Las Vegas","DOI":"10.1109\/ITNG.2009.34"},{"key":"125_CR8","doi-asserted-by":"crossref","unstructured":"Kiezun A, Guo PJ, Jayaraman K, Ernst MD (2009) Automatic creation of SQL injection and cross-site scripting attacks. In: ARDILLA, proceedings of the 31st international conference on software engineering, p 199\u2013209. ICSE, Vancouver","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"125_CR9","doi-asserted-by":"crossref","unstructured":"Kunal S, Mohandas R, Pais AR (2011) Model based hybrid approach to prevent SQL injection attacks in PHP. InfoSecHiComNet\u201911 proceedings of the first international conference on security aspects of information technology, p 3\u201315. Springer, Berlin","DOI":"10.1007\/978-3-642-24586-2_3"},{"key":"125_CR10","unstructured":"Open Web Application Security Project (OWASP) (2012) Top 10 2010-main. https:\/\/www.owasp.org\/index.php\/Top_10_2010-Main . Accessed 13 Jan 2012"},{"issue":"2","key":"125_CR11","first-page":"1","volume":"13","author":"B Prithvi","year":"2010","unstructured":"Prithvi B, Madhusudan P, Venkatakrishnan VN (2010) CANDID: dynamic candidate evaluations for automatic prevention of SQL injection attacks. ACM Trans Inf Syst Secur 13(2):1\u201339","journal-title":"ACM Trans Inf Syst Secur"},{"key":"125_CR12","unstructured":"Qianjie Z, Chen H, Sun J (2010) An execution-flow based method for detecting cross-site scripting attacks. In: Proceedings of software engineering and data mining, p 160\u2013165. SEDM, Shanghai"},{"key":"125_CR13","unstructured":"Rahul J, Sharma P (2012) Survey on web application vulnerabilities (SQLIA,XSS) exploitation and security engine for SQL injection. In: Proceedings on CSNT 2012 IEEE international conference (978-0-7695-4692-6\/1). IEEE, Washington, DC"},{"key":"125_CR14","doi-asserted-by":"crossref","unstructured":"Raju H, Cortesi A (2010) Obfuscation-based analysis of SQL injection attacks. In: ISCC \u201810 proceedings of the IEEE symposium on computers and communications, p 931\u2013938. IEEE, Riccione","DOI":"10.1109\/ISCC.2010.5546750"},{"key":"125_CR15","unstructured":"Rattipong P, Bunyatnoparat P (2011) Protecting cookies from reflected cross sitescript attacks using dynamic cookies rewriting technique. In: Method for detecting cross-site scripting attacks. 13th International conference on advanced communication technology (ICACT), p 1090\u20131094. IEEE Conference Publications, 13\u201316 Feb 2011"},{"key":"125_CR16","doi-asserted-by":"crossref","unstructured":"Stephen WB, Keromytis AD (2004) SQLrand: preventing SQL injection attacks. In: Proceedings of the 2nd applied cryptography and network security (ACNS) conference, p 292\u2013302. ACNS, Yellow Mountain","DOI":"10.1007\/978-3-540-24852-1_21"},{"key":"125_CR17","unstructured":"Stephen T, Williams L, Xie T (2009) On automated prepared statement generation to remove SQL injection vulnerabilities. Department of Computer Science, North Carolina State University, Raleigh"}],"container-title":["International Journal of System Assurance Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-012-0125-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13198-012-0125-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-012-0125-6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T10:48:48Z","timestamp":1744195728000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13198-012-0125-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,9,26]]},"references-count":18,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2012,12]]}},"alternative-id":["125"],"URL":"https:\/\/doi.org\/10.1007\/s13198-012-0125-6","relation":{},"ISSN":["0975-6809","0976-4348"],"issn-type":[{"type":"print","value":"0975-6809"},{"type":"electronic","value":"0976-4348"}],"subject":[],"published":{"date-parts":[[2012,9,26]]}}}