Detection of SQL Injection Attacks by giving apriori to Q-Learning Agents

Tejas Sheth, Janhavi Anap, Het Patel, Nidhi Singh, Ramya B · 2023

Software developers may have created the SQL Injection vulnerability accidentally, or a hacker may have purposefully used it to target vulnerable data. With the recent surge in information, there is an innate quest to safeguard this information from falling into the wrong hand leading to data theft, leak of personal data or loss of property. With relational databases like MySQL being the most popular, it allows users to extract any available information without any significant knowledge of databases. With vast information stored in databases warrants attacker’s attention, potentially risking critical confidential information. The premature detection of SQL Injection Attacks will be very helpful in preventing any malicious attempt by an attacker. In this study, we examine the outcomes of algorithms for reinforcement learning, such as Q-Learning, using a dataset made up of probable SQL Injection queries. We intend to provide a Reinforcement Learning solution to minimise the potential threat posed by SQL Injection and give apriori to the model to learn to detect a SQL attack and prevent any unforeseen mishap more quickly and accurately.

Read the paper · More papers on PaperTik