Multi-Class Classification of Code Injection Attacks Using the Support Vector Machine Algorithm
Hanggoro Seto Firmandani, Mustafa Kamal, Kharisma Monika Dian Pertiwi · 2025
Code injection attacks such as SQL Injection and Cross-Site Scripting remain among the most prevalent and dangerous threats to web applications. This study proposes a multi-class classification system utilizing the Support Vector Machine algorithm to detect and differentiate between SQLi, XSS, and normal web traffic. A comprehensive dataset was constructed by combining both primary data captured via automated attacks on vulnerable features of the OWASP Juice Shop using Caido and secondary data from public repositories. The collected HTTP logs underwent preprocessing, including tokenization and vectorization using Word2Vec. The resulting features were used to train an SVM classifier with a One-vs-Rest strategy. Extensive hyperparameter tuning was performed using GridSearchCV with 5-fold cross-validation. To evaluate its effectiveness, the SVM model was benchmarked against Random Forest, Logistic Regression, and K-Nearest Neighbors, all trained using identical pipelines. The optimized SVM model achieved the highest accuracy of 97.49 %, outperforming the other classifiers in most evaluation metrics. Furthermore, the model was deployed in a real-time detection system, demonstrating robust performance with a detection rate of 88.39 % on a diverse set of unseen attack payloads. The results validate the SVM model's effectiveness for practical and accurate detection of code injection attacks.