Learning to detect SQLIA using node centrality with feature selection

Debabrata Kar, Ajit Kumar Sahoo, Khushboo Agarwal, Suvasini Panigrahi, Madhabananda Das · 2016

Web applications hosted on the Internet are naturally exposed to a variety of attacks and constantly probed by hackers for vulnerabilities. SQL Injection Attack (SQLIA) has been a major security threat on web applications since over 15 years. Detecting SQLIA at runtime is a challenging problem because of extreme heterogeneity of the attack vectors. This paper explores application of node centrality metrics to train a Support Vector Machine (SVM) for identifying malicious queries containing SQL injection attacks. The WHERE clause portion of SQL queries are first normalized into a sequence of tokens and then modeled as interaction networks, from which centrality of the nodes are computed. After applying feature selection by information gain method, the centrality scores of high ranking nodes are used to train the SVM classifier. We experiment with four centrality measures popularly used in Social Network Analysis (SNA). The results on five sample web applications built with PHP/MySQL show that this technique can effectively detect SQLIA with minimal performance overhead. Designed for the database firewall layer, the approach can protect multiple websites on a shared server, which is another advantage.

Read the paper · More papers on PaperTik