Development of a Compressive Framework Using Machine Learning Approaches for SQL Injection Attacks

被引:8
|
作者
Deriba, Fitsum Gizachew [1 ]
SALAU, Ayodeji Olalekan [2 ]
Mohammed, Shaimaa Hadi [3 ]
Kassa, Tsegay Mullu [4 ]
Demilie, Wubetu Barud [4 ]
机构
[1] Wachemo Univ Hossana, Dept Comp Sci, Hossana, Ethiopia
[2] Afe Babalola Univ Ado Ekiti, Dept Elect Elect & Comp Engn, Ado Ekiti, Nigeria
[3] Summer Univ, Dept Comp Sci, Basrah, Iraq
[4] Wachemo Univ, Dept Informat Technol, Hossana, Ethiopia
来源
PRZEGLAD ELEKTROTECHNICZNY | 2022年 / 98卷 / 07期
关键词
SQL injection; Machine Learning; Security flaw; PREVENTION;
D O I
10.15199/48.2022.07.30
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Web applications play an important role in our daily lives. Various Web applications are used to carry out billions of online transactions. Because of their widespread use, these applications are vulnerable to attacks. SQL injection is the most common attack, which accepts user input and runs queries in the backend and returns the desired results. Various approaches have been proposed to counter the SQL injection attack; however, the majority of them have most times failed to cover the entire scope of the problem. This research paper investigates the frequent SQL injection attack forms, their mechanisms, and a way of identifying them based on the SQL query's existence. In addition, we propose a comprehensive framework to determine the effectiveness of the proposed techniques in addressing a number of issues depending on the type of the attack, by using a hybrid (Statistic and dynamic) approach and machine learning. An extensive examination of the model based on a test set indicates that the Hybrid approach and ANN outperforms Naive Bayes, SVM, and Decision tree in terms of accuracy of classifying injected queries. However, with respect to web loading time during testing, Naive Bayes outperforms the other approaches. The proposed Method improved the accuracy of SQL injection attack prevention, according to the test findings.
引用
收藏
页码:181 / 187
页数:7
相关论文
共 50 条
  • [21] An improved filter against injection attacks using regex and machine learning
    Chegu S.
    Reddy G.U.
    Bhambore B.S.
    Adeab K.A.
    Honnavalli P.
    Eswaran S.
    Network Security, 2022, 2022 (09)
  • [22] Detecting Data Injection Attacks in ROS Systems using Machine Learning
    Antunes, Rodrigo Abrantes
    Dalmazo, Bruno L.
    Drews-Jr, Paulo L. J.
    2022 LATIN AMERICAN ROBOTICS SYMPOSIUM (LARS), 2022 BRAZILIAN SYMPOSIUM ON ROBOTICS (SBR), AND 2022 WORKSHOP ON ROBOTICS IN EDUCATION (WRE), 2022, : 223 - 228
  • [23] Detection and Prevention of SQL Injection Attacks Using Semantic Equivalence
    Narayanan, Sandeep Nair
    Pais, Alwyn Roshan
    Mohandas, Radhesh
    COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 103 - 112
  • [24] Prevention of SQL Injection Attacks Using Cryptography and Pattern Matching
    Madhusudhan, R.
    Ahsan, Mohammad
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 624 - 634
  • [25] Preventing SQL Injection Attacks Using Negative Tainting Approach
    Gadgikar, A. S.
    2013 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (ICCIC), 2013, : 115 - 119
  • [26] Detecting SQL injection attacks using query result size
    Jang, Young-Su
    Choi, Jin-Young
    COMPUTERS & SECURITY, 2014, 44 : 104 - 118
  • [27] Shielding Against SQL Injection Attacks Using ADMIRE Model
    Madan, Sushila
    Madan, Supriya
    2009 1ST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS(CICSYN 2009), 2009, : 314 - +
  • [28] Analyzing SQL Meta Characters and Preventing SQL Injection Attacks Using Meta Filter
    Roy, Sangita
    Singh, Avinash Kumar
    Sairam, Ashok Singh
    INFORMATION AND ELECTRONICS ENGINEERING, 2011, 6 : 167 - 170
  • [29] Detection of SQL Injection Attacks using Hidden Markov Model
    Kar, Debabrata
    Agarwal, Khushboo
    Sahoo, Ajit Kumar
    Panigrahi, Suvasini
    PROCEEDINGS OF 2ND IEEE INTERNATIONAL CONFERENCE ON ENGINEERING & TECHNOLOGY ICETECH-2016, 2016, : 1 - 6
  • [30] A Novel Approach for Detecting SQL Injection Attacks Using Snort
    Gupta A.
    Sharma L.S.
    Journal of The Institution of Engineers (India): Series B, 2022, 103 (5) : 1443 - 1451