SQL Injection Attack Detection Framework Based on HTTP Traffic

ZhongDong Zhu, ShiLin Jia, JiShuai Li, Su‐Juan Qin, Hui Guo · 2021

In view of the characteristics of SQL injection attack under the background of complex HTTP traffic, this paper systematically proposes a framework of SQL injection attack detection based on HTTP traffic, including four modules: data collection, data cleaning, feature representation and model building. The data collection module introduces a variety of channels to obtain data, and the flow cleaning module improves the detection ability of SQL injection attack under the complex traffic environment by reducing the interference of irrelevant information. The feature representation module describes an efficient and easy to obtain feature generation method, that is, lexical features that retain special symbols. The model building module proposed a model building method for detecting arbitrary length Payload and a variable length sequence training method to guarantee efficiency. The detection location covers HTTP request headers, URLs, and POST, providing multi-dimensional protection against SQL injection attacks. In the real network environment, the framework detects SQL injection attacks with low alarm omission rate and low false positive rate.

Read the paper · More papers on PaperTik