Journal · 2011
Countering Code Injection Attacks: A Unified Approach
Dimitris Mitropoulos, Vassilios Karakoidas, Panagiotis Louridas, Diomidis Spinellis
One defence against the whole family of code injection attacks that go through an embedded language: give every statement the application is supposed to execute a signature derived from where it appears, and refuse anything else.
- Published in
- Information Management and Computer Security, Vol. 19, No. 3, pp. 177--194, 2011
- Citations
- 17 on Google Scholar, read 5 September 2026 — 10 of 30 by count
- Cite as
- MKLS10
Highly Commended Award, Literati Network Awards for Excellence 2012.
The idea
Server applications reach for dynamic and domain-specific languages — SQL, XPath, JavaScript — and each of those is a vector for injecting code through unchecked input. The countermeasures in circulation were per-language. The observation here is that the attacks share a shape: at the point of execution, the statement is not the one the programmer wrote. So instead of validating input, validate the statement, using location-specific signatures — identifiers that capture characteristics of a statement's execution, including the call site it comes from. A statement whose signature is not on the list was not in the program.
Contributions
- A generic scheme covering the class of injection attacks that use a dynamic or domain-specific language as the vector, rather than one language at a time.
- Detection by location-specific signature rather than input sanitisation, so the defence does not depend on anticipating the attack string.
- Working defences against SQL, XPath and JavaScript injection, demonstrating that the one approach carries across.
- A taxonomy of code injection attacks, separating binary from source-level vectors.
Where it sits
It generalises the XPath paper from 2009, which applied the same idea to one language.
Written from the authors' draft of the paper, which this site hosts; the published version is in Information Management and Computer Security 19(3).