{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T19:08:13Z","timestamp":1781291293754,"version":"3.54.1"},"reference-count":40,"publisher":"Pleiades Publishing Ltd","issue":"6","license":[{"start":{"date-parts":[[2018,11,1]],"date-time":"2018-11-01T00:00:00Z","timestamp":1541030400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2018,11,1]],"date-time":"2018-11-01T00:00:00Z","timestamp":1541030400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Program Comput Soft"],"published-print":{"date-parts":[[2018,11]]},"DOI":"10.1134\/s036176881901002x","type":"journal-article","created":{"date-parts":[[2019,3,6]],"date-time":"2019-03-06T14:03:34Z","timestamp":1551881014000},"page":"435-444","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":48,"title":["NoSQL Injection Attack Detection in Web Applications Using RESTful Service"],"prefix":"10.1134","volume":"44","author":[{"given":"Ahmed M.","family":"Eassa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohamed","family":"Elhoseny","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hazem M.","family":"El-Bakry","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed S.","family":"Salama","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"137","published-online":{"date-parts":[[2019,3,6]]},"reference":[{"key":"7027_CR1","doi-asserted-by":"crossref","unstructured":"Arcuri, A., RESTful API automated test case generation, Proc. 2017 IEEE Int. Conf. on Software Quality, Reliability and Security (QRS), Prague, 2017, pp. 9\u201320.","DOI":"10.1109\/QRS.2017.11"},{"key":"7027_CR2","volume-title":"RESTful API Design: Best Practices in API Design with RESTs","author":"C. Pautasso","year":"2016","unstructured":"Pautasso, C., RESTful API Design: Best Practices in API Design with RESTs, API-Univ., 2016."},{"key":"7027_CR3","doi-asserted-by":"crossref","unstructured":"Zafar, R., Yafi, E., Zuhairi, M.F., and Dao, H., Big data: the NoSQL and RDBMS review, Proc. 2016 Int. Conf. on Information and Communication Technology (ICICTM), Kuala Lumpur, 2016, pp. 120\u2013126.","DOI":"10.1109\/ICICTM.2016.7890788"},{"key":"7027_CR4","first-page":"614","volume":"8","author":"A.M. Eassa","year":"2017","unstructured":"Eassa, A.M., Al-Tarawneh, O.H., El-Bakry, H.M., and Salama, A.S., NoSQL racket: a testing tool for detecting NoSQL injection attacks in web applicationss, Int. J. Adv. Comput. Sci. Appl., 2017, vol. 8, no.\u00a011, pp. 614\u2013622.","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"7027_CR5","doi-asserted-by":"crossref","unstructured":"Okman, L., Gal-Oz, N., Gonen, Y., Gudes, E., and Abramov, J., Security issues in NoSQL databasess, Proc. 10th IEEE Int. Conf. on Trust, Security Privacy Comput. Commun. (TrustCom), Hogn Kong, 2011, pp.\u00a0541\u2013547.","DOI":"10.1109\/TrustCom.2011.70"},{"key":"7027_CR6","unstructured":"Cory, N., Travis, L., Reenu, I., and Gary, H., NoSQL vs RDBMS \u2013 why there is room for boths, Proc. SAIS 2013, Savannah, March 8\u20139, 2013."},{"key":"7027_CR7","doi-asserted-by":"crossref","unstructured":"Schram, A. and Anderson, K.M., MySQL to NoSQL: data modelling challenges in supporting scalabilitys, Proc. 3rd Annu. Conf. on Systems, Programming, and Applications: Software for Humanity SPLASH\u201912, Tucson, 2012, pp. 191\u2013202.","DOI":"10.1145\/2384716.2384773"},{"key":"7027_CR8","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1016\/j.procs.2016.02.057","volume":"78","author":"D. Kaur","year":"2016","unstructured":"Kaur, D. and Kaur, P., Empirical analysis of web attackss, Proc. Comput. Sci., 2016, vol. 78, pp. 298\u2013306.","journal-title":"Proc. Comput. Sci."},{"key":"7027_CR9","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1016\/j.jnca.2015.11.017","volume":"60","author":"V. Prokhorenko","year":"2016","unstructured":"Prokhorenko, V., Kim-Kwang Raymond Choo, and Ashman, H., Web application protection techniques: a taxonomy, J. Network Comput. Appl., 2016, vol. 60, pp.\u00a095\u2013112.","journal-title":"J. Network Comput. Appl."},{"key":"7027_CR10","doi-asserted-by":"publisher","first-page":"170","DOI":"10.4236\/cn.2016.83017","volume":"8","author":"O.M. Rababah","year":"2016","unstructured":"Rababah, O.M., Al Hwaitat, A.K., Al Manaseer, S., Fakhouri, H.N., and Halaseh, R., Web threats detection and prevention frameworks, Commun. Network, 2016, vol. 8, no. 3, pp. 170\u2013178.","journal-title":"Commun. Network"},{"key":"7027_CR11","unstructured":"Tajpour, A., Ibrahim, S., and Sharifi, M., Web application security by SQL injection DetectionTools, Int. J. Comput. Sci., 2012, vol. 9, issue 2, no 3, pp. 332\u2013339."},{"key":"7027_CR12","doi-asserted-by":"crossref","unstructured":"Bherde, G.P. and Pund, M.A., Recent attack prevention techniques in web service applications, Proc. 2016 Int. Conf. on Automatic Control and Dynamic Optimization Techniques (ICACDOT), Pune, 2016, pp. 1174\u20131180.","DOI":"10.1109\/ICACDOT.2016.7877771"},{"key":"7027_CR13","doi-asserted-by":"crossref","unstructured":"Shanmughaneethi, S.V. Emilin Shyni, S.C., and Swamynathan, S., SBSQLID: securing web applications with service based SQL injection detections, Proc. Int. Conf. on Advances in Computing, Control, and Telecommunication Technologies, Trivandrum, Kerala, 2009, pp. 702\u2013704.","DOI":"10.1109\/ACT.2009.178"},{"key":"7027_CR14","doi-asserted-by":"crossref","unstructured":"Jan, S., Panichella, A., Arcuri, A., and Briand, L., Automatic generation of tests to exploit XML injection vulnerabilities in web applications, IEEE Trans. Software Eng., 2017, no. 99.","DOI":"10.1109\/ICST.2017.39"},{"key":"7027_CR15","first-page":"162","volume":"2","author":"R. Shrivastava","year":"2012","unstructured":"Shrivastava, R., Bhattacharyji, J., and Soni, R., SQL injection attacks in database using web service: detection and prevention \u2013 reviews, Asian J. Comput. Sci. Inf. Technol., 2012, vol. 2, no. 6, pp. 162\u2013165.","journal-title":"Asian J. Comput. Sci. Inf. Technol."},{"key":"7027_CR16","doi-asserted-by":"publisher","first-page":"870","DOI":"10.1016\/j.procs.2016.07.265","volume":"93","author":"V.R. Mouli","year":"2016","unstructured":"Mouli, V.R. and Jevitha, K.P., Web services attacks and security \u2013 a systematic literature reviews, Proc. Comput. Sci., 2016, vol. 93, pp. 870\u2013877.","journal-title":"Proc. Comput. Sci."},{"key":"7027_CR17","unstructured":"NoSQL does not have to mean no security: data security and compliance best practices for NoSQL data systems, IBM Corporation, 2016. http:\/\/whitepapers. theregister.co.uk\/paper\/view\/4306\/nosql-does-not-have-to-mean-no-security.pdf. Accessed March, 1 2018."},{"key":"7027_CR18","first-page":"4","volume":"C","author":"A. Lane","year":"2012","unstructured":"Lane, A., Securing big data: security recommendations for hadoop and NoSQL environments, Securosis L.L.C., 2012, pp. 4\u20136.","journal-title":"Securosis L.L."},{"key":"7027_CR19","unstructured":"Amreen and Dadapeer, A survey on robust security mechanism for NoSQL databases, Int. J. Innov. Res. Comput. Commun. Eng., 2016, vol. 4, no. 4, pp. 7662\u20137666."},{"key":"7027_CR20","unstructured":"Ron, A., Shulman-Peleg, A., and Bronshtein, E., No SQL, no injection? Examining NoSQL securitys, Proc. 36th IEEE Symp. on Security and Privacy, San Jose, 2015, vol. 1."},{"key":"7027_CR21","series-title":"NoSQL security","volume-title":"Advances in Computers","author":"N. Gupta","year":"2018","unstructured":"Gupta, N. and Agrawal, R., NoSQL security, in Advances in Computers, Elsevier, 2018."},{"key":"7027_CR22","doi-asserted-by":"crossref","unstructured":"Hou, B., Qian, K., Li, L., Shi, Y., Tao, L., and Liu, J., MongoDB NoSQL injection analysis and detection, Proc. 3rd IEEE Int. Conf. on Cyber Security and Cloud Computing (CSCloud), Beijing, 2016, pp. 75\u201378.","DOI":"10.1109\/CSCloud.2016.57"},{"key":"7027_CR23","first-page":"168","volume":"2","author":"S. Priyadharshini","year":"2017","unstructured":"Priyadharshini, S. and Rajmohan, R., Analysis on database security model against NOSQL injection, Int. J. Sci. Res. Comput. Sci.,\n                           Eng. Inf. Technol., 2017, vol. 2, no. 2, pp. 168\u2013171.","journal-title":"Eng. Inf. Technol."},{"key":"7027_CR24","unstructured":"Sahafizadeh, E. and Nematbakhsh, M.A., A survey on security issues in big data and NoSQLs, ACSIJ J., 2015, vol. 4, issue 4, no.16, pp. 68\u201372."},{"key":"7027_CR25","doi-asserted-by":"crossref","unstructured":"Son, S. and McKinley, K.S., Diglossia: detecting code injection attacks with precision and efficiencys, Proc. 20th ACM Conf. on Computer and Communications Security (CCS), Berlin, 2013, pp. 1181\u20131192.","DOI":"10.1145\/2508859.2516696"},{"key":"7027_CR26","doi-asserted-by":"crossref","first-page":"19","DOI":"10.13189\/wjcat.2013.010201","volume":"1","author":"F.E. Eassa","year":"2012","unstructured":"Eassa, F.E., Zaki, M., Eassa, A.M., and Aljehani, T., IMATT: an integrated multi-agent testing tool for the security of agent-based web applicationss, World J. Comput. Appl. Technol., 2012, vol. 1, no. 2, pp. 19\u201328.","journal-title":"World J. Comput. Appl. Technol."},{"key":"7027_CR27","unstructured":"OWASP Top 10, web application security risks report. http:\/\/www.owasp.org. Accessed March 1, 2018."},{"key":"7027_CR28","unstructured":"CWE\/SANS Top 25 Most Dangerous Software Errors. http:\/\/cwe.mitre.org\/top25\/. Accessed March 1, 2018."},{"key":"7027_CR29","first-page":"520","volume":"29","author":"A.T. Kabakus","year":"2017","unstructured":"Kabakus, A.T. and Kara, R., A performance evaluation of in-memory databasess, J. King Saud Univ. \u2013\n                           Comput. Inf. Sci., 2017, vol. 29, no. 4, pp. 520\u2013525.","journal-title":"Comput. Inf. Sci."},{"key":"7027_CR30","doi-asserted-by":"crossref","unstructured":"Shahriar, H. and Haddad, H.M., Security vulnerabilities of NoSQL and SQL databases for MOOC applicationss, Int. J. Digital Society, 2017, vol. 8, no. 1.","DOI":"10.20533\/ijds.2040.2570.2017.0153"},{"key":"7027_CR31","doi-asserted-by":"publisher","first-page":"1383","DOI":"10.1016\/j.future.2018.03.005","volume":"86","author":"M. Elhoseny","year":"2018","unstructured":"Elhoseny, M., Abdelaziz, A., Salama, A.S., Riad, A.M., Muhammad, K., and Sangaiah, A.K., A hybrid model of Internet of Things and cloud computing to manage big data in health services applicationss, Future Generat. Comput. Syst., 2018, vol. 86, pp. 1383\u20131394.","journal-title":"Future Generat. Comput. Syst."},{"key":"7027_CR32","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/j.measurement.2018.01.022","volume":"119","author":"A. Abdelaziz","year":"2018","unstructured":"Abdelaziz, A., Elhoseny, M., Salama, A.S., and Riad, A.M., A machine learning model for improving healthcare services on cloud computing environments, Measurement, 2018, vol. 119, pp. 117\u2013128.","journal-title":"Measurement"},{"key":"7027_CR33","unstructured":"The DB-Engines Ranking. https:\/\/db-engines.com\/en \/ranking_trend. Accessed March 1, 2018."},{"key":"7027_CR34","volume-title":"REST: from Research to Practicec","author":"E. Wilde","year":"2017","unstructured":"Wilde, E. and Pautasso, C., REST: from Research to Practicec, New York: Springer-Verlag, 2017, pp. 35\u201355."},{"key":"7027_CR35","first-page":"2024","volume":"9","author":"M. Elhoseny","year":"2016","unstructured":"Elhoseny, M., Yuan, X., ElMinir, H.K., and Riad, A.M., An energy efficient encryption method for secure dynamic WSNs, Security Commun. Networks, Wiley, 2016, vol. 9, no. 13, pp. 2024\u20132031.","journal-title":"Networks, Wiley"},{"key":"7027_CR36","doi-asserted-by":"crossref","unstructured":"Elhoseny, M., Elminir, H., Riad, A., and Yuan, X., A\u00a0secure data routing schema for WSN using elliptic curve cryptography and homomorphic encryptions, J. King Saud Univ. \u2013 Comput. Inf. Sci., Elsevier, 2016, vol.\u00a028, no. 3, pp. 262\u2013275.","DOI":"10.1016\/j.jksuci.2015.11.001"},{"key":"7027_CR37","doi-asserted-by":"crossref","unstructured":"Riad, A.M., El-Minir, H.K., and Elhoseny, M., Secure routing in wireless sensor networks: a state of the arts, Int. J. Comput. Appl., 2013, vol. 67, no. 7.","DOI":"10.5120\/11405-6724"},{"key":"7027_CR38","unstructured":"Elhoseny, M., Hosny, A., Hassanien, A.E., Muhammad, K., and Kumar Sangaiah, A., Secure automated forensic investigation for sustainable critical infrastructures compliant with green computing requirements, IEEE Trans. Sust. Comput., 2017, no. 99."},{"key":"7027_CR39","unstructured":"Khari, M., Vaishali. S., and Kumar, M., Comprehensive study of web application attacks and classification, Proc. 3rd Int. Conf. on Computing for Sustainable Global Development (INDIACom), New Delhi, 2016, pp. 2159\u20132164."},{"key":"7027_CR40","doi-asserted-by":"crossref","unstructured":"Selvakumar, G. and Kaviya, B. J., A survey on RESTful web services composition, Proc. Int. Conf. on Computer Communication and Informatics (ICCCI), Coimbatore, 2016, pp. 1\u20134.","DOI":"10.1109\/ICCCI.2016.7479967"}],"container-title":["Programming and Computer Software"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1134\/S036176881901002X.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1134\/S036176881901002X","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1134\/S036176881901002X.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T02:37:00Z","timestamp":1775011020000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1134\/S036176881901002X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,11]]},"references-count":40,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2018,11]]}},"alternative-id":["7027"],"URL":"https:\/\/doi.org\/10.1134\/s036176881901002x","relation":{},"ISSN":["0361-7688","1608-3261"],"issn-type":[{"value":"0361-7688","type":"print"},{"value":"1608-3261","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,11]]},"assertion":[{"value":"20 June 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 March 2019","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}