Intelligent Defense Strategies: Machine Learning-Enhanced SQL Injection Detection and Prevention via Honeypots

B A Manjunatha, K. Aditya Shastry, Mohan M, Aravind · 2024

In the era of digital transformation, injection flaws remain a significant threat, including SQL Injection, Command Injection, LDAP Injection, and No-SQL Injection. This paper focuses on SQL Injection, examining its various attack vectors, underlying causes, and mitigation strategies. Our aim is to enhance detection and prevention methods of this SQL injection threat and safeguard the websites and its crucial data in the database. As a detection strategy, a Random Forest classifier is employed in this setup to distinguish between good and incorrect SQL statements. It gains the ability to discriminate between the two sorts of assertions through training on a dataset that contains samples of each. Using these acquired attributes, the classifier assesses new SQL statements during testing and determines whether they are harmful or not. A 0.76 percent success rate is achieved in the detection of various SQL injection attack types with the use of the Random Forest machine learning model technique. Additionally, a pattern matching mechanism has been linked with the input fields to improve protection.

Read the paper · More papers on PaperTik