Enhancing SQL Injection Detection Using Ensemble Learning and Boosting Models
Yeonjeong Hwang, Thi-Thu-Huong Le, Rini Wisnu Wardhani, Dedy Septono Catur Putranto, Howon Kim · 2024
This paper presents a comparative study of various decision models for detecting SQL injection attacks. SQL injection remains one of the most pervasive and critical security threats to web applications, allowing attackers to gain unauthorized access to databases and manipulate data. Traditional detection methods often fall short due to the evolving nature of attack techniques and the complexity of modern web applications. To address these challenges, we evaluate the performance of Decision Tree, Random Forest, XGBoost, AdaBoost, Gradient Boosting Decision Tree (GBDT), and Histogram Gradient Boosting Decision Tree (HGBDT) on a comprehensive SQL injection dataset. The motivation behind our approach is to leverage the strengths of ensemble learning and boosting techniques to enhance detection accuracy and robustness against SQL injection attacks. By systematically comparing these models, we aim to identify the most effective algorithms for real-time detection systems. Our experimental results demonstrate that Decision Tree, Random Forest, and AdaBoost exhibit superior performance, achieving an accuracy of 99.50% and an F1 score of 99.33%. These findings highlight the potential of ensemble methods in providing reliable and efficient SQL injection detection solutions, paving the way for improved security measures in web applications.