Prevention Of Sql Injection Attack Using Unsupervised Machine Learning Approach
M N Kavitha, V. Vennila, Gopalakrishnan Padmapriya, A. Rajiv Kannan · Int. J. of Aquatic Science · 2021
Now A Day’s Online Web Applications Or Online Database Applications AreIncreasingly Exposed To Various Kinds Of Attacks. One Such Attack To Steal Data IsCalled Sql Injection Attacks In Which Attackers Modify The Sql Query Initiated By TheUser And Adds Malicious Code To Access And Manipulate The Information In The WebApplication Or Database. One Way To Prevent Such Attacks Is To Update And Test WebApplication Firewall (Waf) Regularly. Due To Tremendous Growth In Technology,Attackers Who Intend To Attack The Applications Find Numerous New Ways To EnterInto The System. In This Paper, We Incorporate The Concept Of Machine Learning WithWaf That Maximizes The Effectiveness Of Existing Systems. The Approach Adopted InThis Paper Is Unsupervised Machine Learning Technique Which Uses K-MeansClustering Algorithm. The Flow Of The Proposed System Can Be Given As: The End UserMakes A Query In The Web Application, And The Values Of Query Are Extracted AndSent To The Sql Injection Detector, Which Provides Two Layers Of Security. In The FirstLayer Of Security, Patterns Are Created Using Context-Free Grammar (Cfg) For LowLevel Attacks. The Second Layer Of Security For High Level Attacks Is Trained UsingUnsupervised Learning Algorithm.