Skydd av webbapplikation: En studie om säkerhet mot SQL-injektion
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Protection of Web Applications : A Study on Security Against SQL Injection (English)
Abstract [en]
Web applications often handle sensitive data, so they are the main targets for cyberattacks like SQL injection. Even though there are methods like prepared statements, Object-Relational Mapping and input sanitization, SQL-injection is still a relevant security issue. This study examines how different protection methods work and which factors influence developers’ choices when they work on real projects. The study is based on a review of security standards and how people and organizations work together. It also includes interviews with professional developers about how they handle security.
The study shows that protecting against SQL-injection is not about making a technical decision. The choices that developers make are also influenced by the rules of their organization of what the project needs and if there is code that they must work with. There are certain differences between what theoretical studies recommend and how developers actually write software. The result shows that to have security, highlighting the necessity for advanced security competence among software developers. The organization needs to support them like regular checks of the code and strong focus on security. To reduce the risk of SQL-injection developers need to know the theoretical studies that are recommended and to use it in practice and that means organizations need to support their developers and make security a priority.
Abstract [sv]
Webbapplikationer hanterar ofta känslig information och är därför vanliga mål för cyberattacker. En välkänd sårbarhet är SQL-injektion, där en angripare utnyttjar brister i hur användarinput hanteras i kommunikationen mellan en applikation och en databas. Trots att det finns etablerade skyddsmetoder, såsom prepared statements, ORM-ramverk och sanering, är SQL-injektion fortfarande ett relevant säkerhetsproblem inom systemutveckling.
Denna studie undersöker hur olika skyddsmetoder fungerar samt varför utvecklare gör vissa val när de arbetar med verkliga projekt. Studien bygger på en granskning av säkerhetsstandarder och hur människor och organisationer samarbetar. Studien kompletteras även med intervjuer med professionella utvecklare om hur de hanterar säkerhet. Resultatet visar att skydd mot SQL-injektion inte enbart handlar om att fatta ett tekniskt beslut. De val som utvecklare gör påverkas även av organisatoriska riktlinjer, projektkrav samt befintlig kodbas som de behöver förhålla sig till. Det finns vissa skillnader mellan vad studier visar fungerar bäst och hur utvecklare faktiskt utvecklar programvara. Resultatet visar att för att upprätthålla säkerhet måste utvecklare inneha god kompetens, och organisationen behöver stödja dem genom regelbundna kodgranskningar och ett starkt fokus på säkerhet. För att minska risken för SQL-injektioner behöver utvecklare känna till de teoretiska studier som rekommenderas och använda dem i praktiken, vilket innebär att organisationer måste stödja sina utvecklare och prioritera säkerhet.
Place, publisher, year, edition, pages
2026.
Keywords [en]
SQL-injection, web application security, prepared statements, input sanitization, ORM (Object-Relational Mapping), secure software development, developer decision-making
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:du-54173OAI: oai:DiVA.org:du-54173DiVA, id: diva2:2082690
Subject / course
Microdata Analysis
2026-07-012026-07-01