SQL Injection Attack Detection using ResNet
Sangeeta, S Nagasundari, Prasad B. Honnavalli · 2019
SQL Injection being the top web vulnerabilities, is defined as a code injection technique to gain access over sensitive data. According to OWASP - 2017, it is recorded as one of the top ten web vulnerabilities. Detecting these web vulnerabilities will help to protect sensitive, confidential data. ResNet based SQL injection detection method automatically learns and detects SQL injections attacks. The Tokenizer is used for tokenizing the words, gives word count and vectorize the tokens by converting each token into integer sequence or vector where the coefficient of every token is binary. Processed samples are trained using ResNet algorithm. The user interface is designed for a test case, which expects a user to enter a malicious or normal query. The trained ResNet model is effectively able to identify whether the input request is a malicious or normal request. The results of experiments demonstrate that ResNet can effectively identify different types of SQLIA.