A BiLSTM Approach to Enhance the Accuracy of SQL Injection Attack Detection
Junyi Li · 2024
This paper proposes an innovative method for detecting SQL injection attacks by leveraging the temporal modeling capabilities of Bidirectional Long Short-Term Memory (Bi-LSTM) neural networks. Our approach captures the sequential relationships between traffic packets before and after an intrusion by utilizing a labeled NetFlow V5 dataset. By introducing timestamp information and reprocessing the dataset, the proposed method effectively learns the temporal characteristics of attacks. Comparative experiments demonstrate the superiority of the Bi-LSTM model over unidirectional LSTM and fully connected neural networks, maintaining a false positive rate below 0.22% on the public test set. Furthermore, by incorporating additional injection traffic features, the model's adaptability and effectiveness in real-world attack scenarios are enhanced. The proposed Bi-LSTM based method provides an accurate and efficient solution for detecting SQL injection attacks by using NetFlow data, highlighting the importance of temporal modeling in network intrusion detection.