Application Security using SQL Malware Detection and Prevention Scheme
Dhananjay Kumar Yadav, Mithilesh Kumar Singh Yadav · 2022
SQL (Structure Query Language) injection malware is a harmful instruction intended to cause an adverse effect containing database query that extracts information from the system and supplies unauthenticated access. The SQL queries are less complex and highly flexible, resembling benign queries. In earlier works, such attacks were seen to penetrate the security system of any web application. Machine learning techniques have been applied to various works to trace the SQL malicious query. Also, existing tools such as SEPTIC for the prevention of SQL malware. Earlier models are found to be less robust. This paper introduces an efficient mechanism using SVM (Support vector Machine) to conduct recognition of malware scripts. The SVM is applied to train and test various SQL strings containing benign and malware scripts. The proposed model also performs the prevention of SQL malware attacks. The SQL string prevention is done using a candid dynamic method that performs string analysis. This analysis is used to locate every context of the SQL script and perform its interpretation. In this policy, a parse tree is generated first from the input query. Further, an analysis of the nodes of the parse tree has been performed. The method can identify the benign and malware script. The proposed model is able to secure an average accuracy of 96.24% for detecting and preventing SQL malware queries. Various parameters like true positive rate, false positive rate, true negative rate, and time variation have been calculated concerning data size and accuracy.