Invention Grant
- Patent Title: Database query injection detection and prevention
-
Application No.: US16516599Application Date: 2019-07-19
-
Publication No.: US11057424B2Publication Date: 2021-07-06
- Inventor: Yosef Dinerstein , Oren Yossef , Tomer Weisberg , Assaf Akrabi , Tomer Rotstein
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Liang IP, PLLC
- Main IPC: G06F16/2455
- IPC: G06F16/2455 ; G06F21/62 ; G06F21/55 ; G06F16/24 ; G06F16/23 ; H04L29/06 ; G06F21/64

Abstract:
Computer systems, devices, and associated methods of detecting and/or preventing injection attacks in databases are disclosed herein. In one embodiment, a method includes determining whether parsing a database statement received from an application on the application server cause a syntax error in a database. In response to determining that parsing the received database statement does not cause a syntax error, determining whether an identical syntactic pattern already exists. In response to determining that an identical syntactic pattern already exists in the database, the method includes indicating that the received database statement does not involve an injection attack.
Public/Granted literature
- US20190342332A1 DATABASE QUERY INJECTION DETECTION AND PREVENTION Public/Granted day:2019-11-07
Information query