Detection of SQL injection attacks using Hidden Markov Model

Debabrata Kar, Khushboo Agarwal, Ajit Kumar Sahoo, Suvasini Panigrahi · 2016

SQL Injection Attack (SQLIA) has been consistently ranked among the top security threats against web applications for more than a decade. Nowadays, attackers use sophisticated tools to launch automated injection attacks. The problem of prevention and detection of SQLIA has been long attended by the research community, but hardly any solution exists for protecting multiple websites in a shared hosting environment. In this paper, we present a novel method to detect malicious queries using a twin Hidden Markov Model (HMM) ensemble and validate it with large set of benign and malicious queries collected from five sample web applications written in PHP and MySQL. Following the Multiple Classifier System (MCS) paradigm, we combine the output of individual HMMs to arrive at the final decision, which provides better accuracy and lower false alarms. The system is intended to work at the database firewall layer, therefore it can protect multiple web applications hosted on a shared server. The initial experimental results are very encouraging and indicate that the approach can effectively identify wide varieties of SQLIA with negligible impact on performance. The technique can be easily ported to other languages and database platforms without requiring major modifications.

Read the paper · More papers on PaperTik