Determining Web Application Vulnerabilities Using Machine Learning Methods

Aidana Zhumabekova, Eric T. Matson, Vladislav Karyukin, Kuanysh Zhumabekova, Berik Zhuandykov, Olga Ussatova, Tansholpan Telbayeva · 2023

Information technology is a significant factor in the modern world. This area is developing quickly, becoming essential as new, more complex protection methods appear. Threat detection instruments have also been actively developing for recent decades. The available scanning systems allow to disclose many threats. Moreover, machine and deep learning Artificial intelligence methods have been developing significantly. With so many penetration testing scanners available, choosing the most effective scanner can be daunting as it depends on the specific testing environment. This paper focuses on detecting SQL injection threats with the use of such machine learning algorithms as Naïve Bayes, Support Vector Machine, Decision Tree, Random Forest, XGBoost, and CatBoost. The analyzed dataset contains safe and dangerous SQL commands that various websites have been exposed to. The classification model results showed that most applied algorithms demonstrated perfect accuracy, precision, recall, and F1-score values above 0.95. These high scores proved to be efficient in the SQL injection classification tasks.

Read the paper · More papers on PaperTik