当前全球进入网络信息一体化时代,网络信息安全问题应运而生。从列举日趋高发的SQL注入攻击事件入手,阐述了SQL注入攻击概念、特点,然后通过一个实例讲解了攻击的一般过程,最后按照从程序开发到应用这个顺序,提出了We b应用程序防御SQL注入攻击的全过程安全策略。
Currently the world gets into the information era,the network information security problems arise at the historic moment.This paper began with the worsening instances of SQL injection attack,we explained the principle and characteristics of SQL injection,then expounded the process of attack through an example.Finally,a defensive method for SQL injection called whole process security policy had been proposed for web sites