SQL Injection Attack Detection in Web Applications Using Machine Learning Algorithms
Saravanan Tamilselvan, Kevin C. France · 2025
One of the major threats to the security of web applications continues to be the SQL injection (SQLi), which allows the attackers to modify the database query for illegal data access. Traditional SQL injection detection techniques, e.g., rule- or signature-based detection methods, have often failed to catch up with the evolution of attack patterns. To remedy this shortcoming, we propose a machine learning-based detection system, using Random Forest (RF) and XGBoost (XGB) models, to classify SQL queries into either benign or malicious. In our methodology, we perform feature extraction using TF-IDF (Term Frequency-Inverse Document Frequency), balance the data with SMOTE (Synthetic Minority Over-Sampling Technique), and apply hyperparameter tuning using GridSearchCV. In addition, we employ a voting classifier to combine the advantages of both RF and XGB for enhanced detection accuracy and robustness. Experimental results on the modified SQL injection dataset have shown that the combined model achieves an accuracy of 99.46%, while being more stable and generalizable than the individual models. Moreover, for enhancing security in real-world applications, we incorporate multi-factor authentication (MFA) and automated alerting mechanisms. This work tells us that the combination of these ensemble learning techniques can tremendously improve SQL injection detection by lowering false positives and false negatives.