Detection of SQL Injection Attacks Using Machine Learning Techniques
RDN Shakya, D. N. S. Dharmaratne, Manjula Sandirigama · 2024
As listed in the Open Worldwide Application Security Project (OWASP), injections are one of the most frequent threats to web applications. SQL injections (SQLi) took precedence among the injections. This research focused on SQLi attack detection with the aid of Machine Learning (ML) techniques. Standing strong on the thorough literary review, the study tried to find a meaningfully capable set of ML algorithms that could be utilized to design and develop a real-time SQLi attack detection model. The research experiment utilized K-Nearest Neighbor (KNN), Support Vector Machine (SVM), and Random Forest (RF) to fulfill the primary research aim, which is the detection of SQLi attacks. The research used a dataset which consisted of 53,261 data points of both SQLi attack payloads and non-malicious payloads. The SQLi attack payloads covered a wide range of different SQL statements. After the implementation of the experimental designs for three separate ML models, the performance results metrics were generated. As the ML model performance results metrics, it uses classification accuracy, classification error, precision, true positive rate, false positive rate, and specificity. The KNN algorithm achieved 99.55% accuracy, while RF achieved 87.72% and the SVM achieved 98.28%. The KNN algorithm secured the highest rate of accuracy among the three models for SQLi attack detection. The findings of the research show the potential of ML models in SQLi attack detection. The research results can be utilized for the development of ML-enabled attack detection solutions particularly for web applications.