Cyber Attack Detection Method Based on NLP and Ensemble Learning Approach

Maheli Ahmed, Mohammed Nasir Uddin · 2020

In recent years the use of web applications has gone through fast growth. Billions of transactions, sharing information over the Internet have become a common phenomenon because of web applications. Users send necessary and confidential information to web-based applications and store them into databases. Web applications and connected databases are accessible through the Internet, which makes them prone to cyber-attacks. SQL Injection is a cyber-attack that is most pervasive. Attackers steal intended information by injecting SQL codes. Users of web applications could face damaging effects for SQL Injection. Through this research work, a SQL Injection detection method is proposed, which uses Natural Language Processing (NLP) and Ensemble Learning Algorithm. NLP generates feature patterns, extracts features, transforms each text into numerical representation in the form of a vector, and generates a bag-of-words model (BoW model). BoW model trains Random Forest Classifier. The Random Forest Classifier is an ensemble learning algorithm. This algorithm combines several machine learning algorithms and builds one predictive model to get a better detection ability. The trained classifier classifies SQL Injection payloads with higher accuracy from the dataset.

Read the paper · More papers on PaperTik