Web Anomaly Misuse Intrusion Detection Framework for SQL Injection Detection
Shaimaa Ezzat, I. Mohamed, M. N. Nor Laila, Khaled Yehia · International Journal of Advanced Computer Science and Applications · 2012
Databases at the background of e-commerce applications are vulnerable to SQL injection attack which is considered as one of the most dangerous web attacks. In this paper we propose a framework based on misuse and anomaly detection techniques to detect SQL injection attack. The main idea of this framework is to create a profile for legitimate database behavior extracted from applying association rules on XML file containing queries submitted from application to the database. As a second step in the detection process, the structure of the query under observation will be compared against the legitimate queries stored in the XML file thus minimizing false positive alarms.