A Novel Approach Exploiting Machine Learning to Detect SQLi Attacks

被引:3
|
作者
Ashlam, Ahmed Abadulla [1 ]
Badii, Atta [1 ]
Stahl, Frederic [2 ]
机构
[1] Univ Reading, Dept Comp Sci, Reading, Berks, England
[2] German Res Ctr Artificial Intelligence GmbH DFKI, Lab Niedersachsen, Marine Percept, D-26129 Oldenburg, Germany
关键词
Data mining; OWASP; SQL injection; attacks; false positive; false negative; CountVectorizer; INJECTION ATTACK;
D O I
10.1109/IC_ASET53395.2022.9765948
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The increasing use of Information Technology applications in the distributed environment is increasing security exploits. Information about vulnerabilities is also available on the open web in an unstructured format that developers can take advantage of to fix vulnerabilities in their IT applications. SQL injection (SQLi) attacks are frequently launched with the objective of exfiltration of data typically through targeting the back-end server organisations to compromise their customer databases. There have been a number of high profile attacks against large enterprises in recent years. With the ever-increasing growth of online trading, it is possible to see how SQLi attacks can continue to be one of the leading routes for cyber-attacks in the future, as indicated by findings reported in OWASP. Various machine learning and deep learning algorithms have been applied to detect and prevent these attacks. However, such preventive attempts have not limited the incidence of cyber-attacks and the resulting compromised database as reported by (CVE) repository. In this paper, the potential of using data mining approaches is pursued in order to enhance the efficacy of SQL injection safeguarding measures by reducing the false-positive rates in SQLi detection. The proposed approach uses CountVectorizer to extract features and then apply various supervised machine-learning models to automate the classification of SQLi. The model that returns the highest accuracy has been chosen among available models. Also a new model has been created PALOSDM (Performance analysis and Iterative optimisation of the SQLI Detection Model) for reducing false-positive rate and false-negative rate. The detection rate accuracy has also been improved significantly from a baseline of 94% up to 99%.
引用
收藏
页码:513 / 517
页数:5
相关论文
共 50 条
  • [1] Hybrid Approach to Detect SQLi Attacks and Evasion Techniques
    Makiou, Abdelhamid
    Begriche, Youcef
    Serhrouchni, Ahmed
    [J]. 2014 INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING (COLLABORATECOM), 2014, : 452 - 456
  • [2] A Novel Approach to Detect Phishing Attacks using Binary Visualisation and Machine Learning
    Barlow, Luke
    Bendiab, Gueltoum
    Shiaeles, Stavros
    Savage, Nick
    [J]. 2020 IEEE WORLD CONGRESS ON SERVICES (SERVICES), 2020, : 177 - 182
  • [3] Securing web applications against XSS and SQLi attacks using a novel deep learning approach
    Jaydeep R. Tadhani
    Vipul Vekariya
    Vishal Sorathiya
    Samah Alshathri
    Walid El-Shafai
    [J]. Scientific Reports, 14
  • [4] Securing web applications against XSS and SQLi attacks using a novel deep learning approach
    Tadhani, Jaydeep R.
    Vekariya, Vipul
    Sorathiya, Vishal
    Alshathri, Samah
    El-Shafai, Walid
    [J]. SCIENTIFIC REPORTS, 2024, 14 (01)
  • [5] An efficient approach to detect IoT botnet attacks using machine learning
    Alothman, Zainab
    Alkasassbeh, Mouhammd
    Baddar, Sherenaz Al-Haj
    [J]. JOURNAL OF HIGH SPEED NETWORKS, 2020, 26 (03) : 241 - 254
  • [6] Ascertain the efficient machine learning approach to detect different ARP attacks
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    Nehra, Ajay
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 99
  • [7] A Novel Machine Learning Approach to Detect Phishing Websites
    Tyagi, Ishant
    Shad, Jatin
    Sharma, Shubham
    Gaur, Siddharth
    Kaur, Gagandeep
    [J]. 2018 5TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2018, : 425 - 430
  • [8] A Novel Distributed Machine Learning Model to Detect Attacks on Edge Computing Network
    Trong-Minh Hoang
    Trang-Linh Le Thi
    Nguyen Minh Quy
    [J]. JOURNAL OF ADVANCES IN INFORMATION TECHNOLOGY, 2023, 14 (01) : 153 - 159
  • [9] Detection and prevention of SQLI attacks and developing compressive framework using machine learning and hybrid techniques
    Wubetu Barud Demilie
    Fitsum Gizachew Deriba
    [J]. Journal of Big Data, 9
  • [10] Detection and prevention of SQLI attacks and developing compressive framework using machine learning and hybrid techniques
    Demilie, Wubetu Barud
    Deriba, Fitsum Gizachew
    [J]. JOURNAL OF BIG DATA, 2022, 9 (01)