如何在GridDB这类NoSQL数据库中防范注入攻击?
GridDB与.NET结合的注入攻击防范问题
基于.NET开发的应用可借助其针对SQL数据库的内置功能保障安全。我此前在项目中使用SQL Server,但受限于它的水平扩展能力,转而采用以高性能与可扩展性著称的GridDB。
不过我担忧NoSQL数据库的安全风险,此前项目中我使用.NET提供的**依赖注入(Dependency Injection)**服务配合参数化查询防范SQL注入攻击,相关内容可参考.NET Core官方文档。
此前SQL Server项目中的依赖注入配置示例
using System; using System.Collections.Generic; using System.Linq; using System.Text; using System.Threading.Tasks; using Microsoft.Extensions.DependencyInjection; using EmployeeManagementDAL.Interface; using EmployeeManagementDAL; namespace EmployeeManagementBL { public static class Injection { public static void DependencyInjection(this IServiceCollection service) { service.AddTransient<EmployeeRepoInterface, EmployeeRepo>(); } } }
SQL Server中使用参数化查询实现addEmployee的示例
public void addEmployee(Employee emp) { DynamicParameters parameters = new DynamicParameters(); parameters.Add("@Name", emp.Name, DbType.String); parameters.Add("@Designation", emp.Designation, DbType.String); parameters.Add("@Department", emp.Department, DbType.String); string output_query = "INSERT INTO [dbo].[Employee] (Name, Designation, Department) VALUES (@Name, @Designation, @Department);"; IDbConnection connection = null; using (connection = new SqlConnection(connectionString)) { if (connection.State != ConnectionState.Open) { connection.Open(); } connection.Query<Employee>(output_query, parameters); connection.Close(); } }
我编写的GridDB版本AddEmployee函数
public void AddEmployee(Employee emp) { using (GSGrid store = new GSGrid("myCluster")) { using (GSTimeSeries<Employee> employeeContainer = store.GetTimeSeries<Employee>("EmployeeContainer")) { Employee newEmployee = new Employee { Name = emp.Name, Designation = emp.Designation, Department = emp.Department }; employeeContainer.Put(newEmployee); } } }
我没有找到.NET与GridDB结合使用参数化查询的方法,因此想了解GridDB是否提供内置功能来防范注入攻击,降低注入漏洞风险。
内容的提问来源于stack exchange,提问作者Ismail
相关产品推荐
相关产品推荐

