SQL Injection Attacks Detection and Prevention Based on Neuro-Fuzzy Technique

被引:0
|
作者
Nofal, Doaa E. [1 ]
Amer, Abeer A. [2 ]
机构
[1] Alexandria Univ, Inst Grad Studies & Res, Alexandria, Egypt
[2] Sadat Acad Management & Sci, Alexandria, Egypt
关键词
SQL injection attacks; Neuro-fuzzy; ANFIS; FCM; SCG; Web security;
D O I
10.1007/978-3-030-31129-2_66
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Structured Query Language (SQL) injection attack (SQLIA) is one of most famous code injection techniques that threaten web applications, as it could compromise the confidentiality, integrity and availability of the database system of an online application. Whereas other known attacks follow specific patterns, SQLIAs are often unpredictable and demonstrate no specific pattern, which has been greatly problematic to both researchers and developers. Therefore, the detection and prevention of SQLIAs has been a hot topic. This paper proposes a system to provide better results for SQLIA prevention than previous methodologies, taking in consideration the accuracy of the system and its learning capability and flexibility to deal with the issue of uncertainty. The proposed system for SQLIA detection and prevention has been realized on an Adaptive Neuro-Fuzzy Inference System (ANFIS). In addition, the developed system has been enhanced through the use of Fuzzy C-Means (FCM) to deal with the uncertainty problem associated with SQL features. Moreover, Scaled Conjugate Gradient algorithm (SCG) has been utilized to increase the speed of the proposed system drastically. The proposed system has been evaluated using a well-known dataset, and the results show a significant enhancement in the detection and prevention of SQLIAs.
引用
收藏
页码:722 / 738
页数:17
相关论文
共 50 条
  • [1] Detection and prevention of SQL injection attacks
    Halfond, William G. J.
    Orso, Alessandro
    MALWARE DETECTION, 2007, : 85 - +
  • [2] A Simple and Fast Technique for Detection and Prevention of SQL Injection Attacks (SQLIAs)
    Lashkaripour, Z.
    Bafghi, A. Ghaemi
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (05): : 53 - 66
  • [3] A Framework for the Detection and Prevention of SQL Injection Attacks
    Shafie, Emad
    Cau, Antonio
    PROCEEDINGS OF THE 11TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 329 - 336
  • [4] A Survey on SQL Injection Attacks, Detection and Prevention
    Hu, Jianwei
    Zhao, Wei
    Cui, Yanpeng
    ICMLC 2020: 2020 12TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND COMPUTING, 2018, : 483 - 488
  • [5] A Hybrid Method for Detection and Prevention of SQL Injection Attacks
    Ghafarian, Ahmad
    2017 COMPUTING CONFERENCE, 2017, : 833 - 838
  • [6] Detection and Prevention of SQL Injection Attacks on Web Applications
    Fouad, Yasser
    Elshazly, Khaled
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (08): : 1 - 7
  • [7] A Survey on SQL Injection Attacks, Detection and Prevention Techniques
    Kumar, Puspendra
    Pateriya, R. K.
    2012 THIRD INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION & NETWORKING TECHNOLOGIES (ICCCNT), 2012,
  • [8] Detection and Prevention of SQL Injection Attacks Using Semantic Equivalence
    Narayanan, Sandeep Nair
    Pais, Alwyn Roshan
    Mohandas, Radhesh
    COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 103 - 112
  • [9] A Novel Intrusion Detection and Prevention Model for SQL Injection Attacks
    Ali, Malik Rizwan
    Malik, Muhammad Sheraz Arshad
    Hameed, Noureen
    Tahir, Faizan
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (08): : 91 - 97
  • [10] A systematic review of detection and prevention techniques of SQL injection attacks
    Nasereddin, Mohammed
    ALKhamaiseh, Ashaar
    Qasaimeh, Malik
    Al-Qassas, Raad
    INFORMATION SECURITY JOURNAL, 2023, 32 (04): : 252 - 265