A Hybrid Approach to Detect Injection Attacks on Server-Side Applications Using Data Mining Techniques
Abu Syeed Sajid Ahmed, Mehjabeen Shachi, Afsana Afrin Brishty, Nurnaby Siddiqui, Nazmus Sakib · 2021
Cyber attacks are one of the most serious concerns facing individuals at all levels, particularly in enterprises, as they can maliciously destroy systems and steal data. Cyber-attacks are normally carried out by a hacker group to attack a single computer or networks. An attacker launches a serverside attack directly at a listening service. Server-side attacks aim to compromise and infringe on a server's data and applications. Attackers are mostly interested in email services, media players, web browsers, office suites, and other similar apps. Attackers can more easily target server-side applications due to malicious requests. In our work, a hybrid approach is implemented inside our proposed two-layer security firewall that includes both machine learning and non-machine learning approaches to detect malicious codes. In the machine learning-based approach, Adaboost and Random Forest are evaluated as the best classifiers with the accuracy 97.9% for detecting SQL injection attacks. On the other hand, SVM performed better than other classifiers with an accuracy of 91.5% for detecting NoSQL injection attacks.