SQL Injection Attacks Detection and Prevention Based on Neuro-Fuzzy Technique

被引:0
|
作者
Nofal, Doaa E. [1 ]
Amer, Abeer A. [2 ]
机构
[1] Alexandria Univ, Inst Grad Studies & Res, Alexandria, Egypt
[2] Sadat Acad Management & Sci, Alexandria, Egypt
关键词
SQL injection attacks; Neuro-fuzzy; ANFIS; FCM; SCG; Web security;
D O I
10.1007/978-3-030-31129-2_66
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Structured Query Language (SQL) injection attack (SQLIA) is one of most famous code injection techniques that threaten web applications, as it could compromise the confidentiality, integrity and availability of the database system of an online application. Whereas other known attacks follow specific patterns, SQLIAs are often unpredictable and demonstrate no specific pattern, which has been greatly problematic to both researchers and developers. Therefore, the detection and prevention of SQLIAs has been a hot topic. This paper proposes a system to provide better results for SQLIA prevention than previous methodologies, taking in consideration the accuracy of the system and its learning capability and flexibility to deal with the issue of uncertainty. The proposed system for SQLIA detection and prevention has been realized on an Adaptive Neuro-Fuzzy Inference System (ANFIS). In addition, the developed system has been enhanced through the use of Fuzzy C-Means (FCM) to deal with the uncertainty problem associated with SQL features. Moreover, Scaled Conjugate Gradient algorithm (SCG) has been utilized to increase the speed of the proposed system drastically. The proposed system has been evaluated using a well-known dataset, and the results show a significant enhancement in the detection and prevention of SQLIAs.
引用
收藏
页码:722 / 738
页数:17
相关论文
共 50 条
  • [41] Neuro-fuzzy system for chemical agent detection
    Tampere Univ of Technology, Tampere, Finland
    IEEE Trans Fuzzy Syst, 4 (415-424):
  • [42] Neuro-fuzzy based nonlinear models
    Nitu, C.
    Dobrescu, A.
    DEVICE APPLICATIONS OF NONLINEAR DYNAMICS, 2006, : 237 - 244
  • [43] Neuro-fuzzy learning for automated incident detection
    Viswanathan, M.
    Lee, S. H.
    Yang, Y. K.
    ADVANCES IN APPLIED ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2006, 4031 : 889 - 897
  • [44] NFIDS: A neuro-fuzzy intrusion detection system
    Mohajerani, M
    Moeini, A
    Kianie, M
    ICECS 2003: PROCEEDINGS OF THE 2003 10TH IEEE INTERNATIONAL CONFERENCE ON ELECTRONICS, CIRCUITS AND SYSTEMS, VOLS 1-3, 2003, : 348 - 351
  • [45] Neuro-fuzzy based constraint programming
    Yazdi, Hadi Sadoghi
    Hosseini, S. E.
    Yazdi, Mehri Sadoghi
    APPLIED MATHEMATICAL MODELLING, 2010, 34 (11) : 3547 - 3559
  • [46] Neuro-Fuzzy Based Intrusion Detection System for Wireless Sensor Network
    Sinha, Somnath
    Paul, Aditi
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 114 (01) : 835 - 851
  • [47] Neuro-Fuzzy Based Fault Detection Identification and Location in a Distribution Network
    Babayomi, Oluleke
    Oluseyi, Peter
    Keku, Godbless
    Ofodile, Nkemdilim A.
    2017 IEEE PES POWERAFRICA CONFERENCE, 2017, : 164 - 168
  • [48] Neuro-Fuzzy Based Intrusion Detection System for Wireless Sensor Network
    Somnath Sinha
    Aditi Paul
    Wireless Personal Communications, 2020, 114 : 835 - 851
  • [49] Prevention of SQL Injection Attacks Using Cryptography and Pattern Matching
    Madhusudhan, R.
    Ahsan, Mohammad
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 624 - 634
  • [50] Detection of SQL Injection Attacks: A Machine Learning Approach
    Hasan, Musaab
    Balbahaith, Zayed
    Tarique, Mohammed
    2019 INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTING TECHNOLOGIES AND APPLICATIONS (ICECTA), 2019,