Development of a Compressive Framework Using Machine Learning Approaches for SQL Injection Attacks

被引:8
|
作者
Deriba, Fitsum Gizachew [1 ]
SALAU, Ayodeji Olalekan [2 ]
Mohammed, Shaimaa Hadi [3 ]
Kassa, Tsegay Mullu [4 ]
Demilie, Wubetu Barud [4 ]
机构
[1] Wachemo Univ Hossana, Dept Comp Sci, Hossana, Ethiopia
[2] Afe Babalola Univ Ado Ekiti, Dept Elect Elect & Comp Engn, Ado Ekiti, Nigeria
[3] Summer Univ, Dept Comp Sci, Basrah, Iraq
[4] Wachemo Univ, Dept Informat Technol, Hossana, Ethiopia
来源
PRZEGLAD ELEKTROTECHNICZNY | 2022年 / 98卷 / 07期
关键词
SQL injection; Machine Learning; Security flaw; PREVENTION;
D O I
10.15199/48.2022.07.30
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Web applications play an important role in our daily lives. Various Web applications are used to carry out billions of online transactions. Because of their widespread use, these applications are vulnerable to attacks. SQL injection is the most common attack, which accepts user input and runs queries in the backend and returns the desired results. Various approaches have been proposed to counter the SQL injection attack; however, the majority of them have most times failed to cover the entire scope of the problem. This research paper investigates the frequent SQL injection attack forms, their mechanisms, and a way of identifying them based on the SQL query's existence. In addition, we propose a comprehensive framework to determine the effectiveness of the proposed techniques in addressing a number of issues depending on the type of the attack, by using a hybrid (Statistic and dynamic) approach and machine learning. An extensive examination of the model based on a test set indicates that the Hybrid approach and ANN outperforms Naive Bayes, SVM, and Decision tree in terms of accuracy of classifying injected queries. However, with respect to web loading time during testing, Naive Bayes outperforms the other approaches. The proposed Method improved the accuracy of SQL injection attack prevention, according to the test findings.
引用
收藏
页码:181 / 187
页数:7
相关论文
共 50 条
  • [1] Detecting SQL Injection Attacks in Cloud SaaS using Machine Learning
    Tripathy, Dharitri
    Gohil, Rudrarajsinh
    Halabi, Talal
    2020 IEEE 6TH INT CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / 6TH IEEE INT CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) / 5TH IEEE INT CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2020, : 145 - 150
  • [2] Detection of SQL Injection Attacks: A Machine Learning Approach
    Hasan, Musaab
    Balbahaith, Zayed
    Tarique, Mohammed
    2019 INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTING TECHNOLOGIES AND APPLICATIONS (ICECTA), 2019,
  • [3] Mitigation of SQL Injection Attacks through Machine Learning Classifier
    Anu, P.
    Ramani, G.
    Mohanapriya, D.
    Ganesh, R. Karthik
    Kalyani, N.
    2ND INTERNATIONAL CONFERENCE ON SUSTAINABLE COMPUTING AND SMART SYSTEMS, ICSCSS 2024, 2024, : 606 - 611
  • [4] SQL Injection Detection using Machine Learning
    Joshi, Anamika
    Geetha, V
    2014 INTERNATIONAL CONFERENCE ON CONTROL, INSTRUMENTATION, COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICCICCT), 2014, : 1111 - 1115
  • [5] Ensemble Machine Learning Approaches for Detection of SQL Injection Attack
    Farooq, Umar
    TEHNICKI GLASNIK-TECHNICAL JOURNAL, 2021, 15 (01): : 112 - 120
  • [6] A Framework for the Detection and Prevention of SQL Injection Attacks
    Shafie, Emad
    Cau, Antonio
    PROCEEDINGS OF THE 11TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 329 - 336
  • [7] SQL Injection Detection Using Machine Learning Techniques
    Hosam, Eman
    Hosny, Hagar
    Ashraf, Walaa
    Kaseb, Ahmed S.
    2021 8TH INTERNATIONAL CONFERENCE ON SOFT COMPUTING & MACHINE INTELLIGENCE (ISCMI 2021), 2021, : 15 - 20
  • [8] USING SNORT IN SQL INJECTION ATTACKS
    AlNabulsi, Hussein
    Alsmadi, Izzat
    AlJarrah, Mohammad
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2020, 14 (02): : 37 - 46
  • [9] Detection and prevention of SQLI attacks and developing compressive framework using machine learning and hybrid techniques
    Demilie, Wubetu Barud
    Deriba, Fitsum Gizachew
    JOURNAL OF BIG DATA, 2022, 9 (01)
  • [10] Detection and prevention of SQLI attacks and developing compressive framework using machine learning and hybrid techniques
    Wubetu Barud Demilie
    Fitsum Gizachew Deriba
    Journal of Big Data, 9