A Machine Learning Methodology for Detecting SQL Injection Attacks

Anish Gupta, Lalit Kumar Tyagi, Aezeden Mohamed · 2023

In today's environment, we all rely on web applications. The number of web application users is growing by the day. Most organizations use databases to hold data about their users or information about the services they provide. Structured Query Language is frequently used for database communication. During a SQL Injection attack, the attacker runs a malicious SQL statement on the database. Since SQL injection can be used to alter database values, wipe out the entire database, and steal database content, it poses a serious security risk. Attackers can acquire unauthorized access to the entire database by using SQL injection. SQL Injection attacks are feasible when a web application fails to check or filter user- entered input. SQL injection threats are both detected and analyzed using machine learning methods such as naive Bayes, Gradient Boosting, Support Vector Machine, Decision Tree, and Convolution Neural Network.

Read the paper · More papers on PaperTik