Deep Learning-Based Detection Technology for SQL Injection Research and Implementation

被引:1
|
作者
Sun, Hao [1 ]
Du, Yuejin [2 ]
Li, Qi [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Cyberspace Secur Acad, Beijing 100876, Peoples R China
[2] Beijing Qihoo Technol Co Ltd, Beijing 100015, Peoples R China
来源
APPLIED SCIENCES-BASEL | 2023年 / 13卷 / 16期
基金
中国国家自然科学基金;
关键词
deep learning; SQL injection detection; TextCNN; LSTM;
D O I
10.3390/app13169466
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Amid the incessant evolution of the Internet, an array of cybersecurity threats has surged at an unprecedented rate. A notable antagonist within this plethora of attacks is the SQL injection assault, a prevalent form of Internet attack that poses a significant threat to web applications. These attacks are characterized by their extensive variety, rapid mutation, covert nature, and the substantial damage they can inflict. Existing SQL injection detection methods, such as static and dynamic detection and command randomization, are principally rule-based and suffer from low accuracy, high false positive (FP) rates, and false negative (FN) rates. Contemporary machine learning research on SQL injection attack (SQLIA) detection primarily focuses on feature extraction. The effectiveness of detection is heavily reliant on the precision of feature extraction, leading to a deficiency in tackling more intricate SQLIA. To address these challenges, we propose a novel SQLIA detection approach harnessing the power of an enhanced TextCNN and LSTM. This method begins by vectorizing the samples in the corpus and then leverages an improved TextCNN to extract local features. It then employs a Bidirectional LSTM (Bi-LSTM) network to decipher the sequence information inherent in the samples. Given LSTM's modest effectiveness for relatively long sequences, we further integrate an attention mechanism, reducing the distance between any two words in the sequence to one, thereby enhancing the model's effectiveness. Moreover, pre-trained word vector features acquired via BERT for transfer learning are incorporated into the feature section. Comparative experimental results affirm the superiority of our deep learning-based SQLIA detection approach, as it effectively elevates the SQLIA recognition rate while reducing both FP and FN rates.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] Research on Deep Learning-based Object Detection Algorithm in Construction Sites
    School of Computer Science and Software Engineering, University of Science and Technology Liaoning, Anshan
    114051, China
    Eng. Lett., 2025, 33 (01): : 1 - 12
  • [22] Review on Research and Application of Deep Learning-Based Target Detection Algorithms
    Zhang, Yangting
    Huang, Deqi
    Wang, Dongwei
    He, Jiajia
    Computer Engineering and Applications, 2023, 59 (18) : 1 - 13
  • [23] Review of deep learning-based false data injection attack detection in power systems
    Li, Zhuo
    Xie, Yaobin
    Wu, Qianqiong
    Zhang, Youwei
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2024, 52 (19): : 175 - 187
  • [24] A Multimodal Deep Learning-Based Fault Detection Model for a Plastic Injection Molding Process
    Kim, Gyeongho
    Choi, Jae Gyeong
    Ku, Minjoo
    Cho, Hyewon
    Lim, Sunghoon
    IEEE ACCESS, 2021, 9 : 132455 - 132467
  • [25] Deep Neural Network-Based SQL Injection Detection Method
    Zhang, Wei
    Li, Yueqin
    Li, Xiaofeng
    Shao, Minggang
    Mi, Yajie
    Zhang, Hongli
    Zhi, Guoqing
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [26] Research of SQL Injection Attack and Prevention Technology
    Qian, Li
    Zhu, Zhenyuan
    Hu, Lun
    Liu, Shuying
    PROCEEDINGS OF 2015 INTERNATIONAL CONFERENCE ON ESTIMATION, DETECTION AND INFORMATION FUSION ICEDIF 2015, 2015, : 303 - 306
  • [27] A Note on Implementation Methodologies of Deep Learning-Based Signal Detection for Conventional MIMO Transmitters
    Xia, Junjuan
    Deng, Dan
    Fan, David
    IEEE TRANSACTIONS ON BROADCASTING, 2020, 66 (03) : 744 - 745
  • [28] Deep Learning-based Attacks on Masked AES Implementation
    Daehyeon, Bae
    Hwang, Jongbae
    Ha, Jaecheol
    JOURNAL OF INTERNET TECHNOLOGY, 2022, 23 (04): : 897 - 902
  • [29] RESEARCH ON DEEP LEARNING-BASED ALGORITHM FOR DIGITAL IMAGE COMBINATION AND TARGET DETECTION
    Huang, Shanlu
    Lai, Jialin
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2024, 25 (05): : 4023 - 4031
  • [30] A Deep Learning-Based SAR Ship Detection
    Yu, Chushi
    Shin, Yoan
    2023 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE IN INFORMATION AND COMMUNICATION, ICAIIC, 2023, : 744 - 747