A Machine Learning Based Approach to Identify SQL Injection Vulnerabilities

A Machine Learning Based Approach to Identify SQL Injection Vulnerabilities
复制标题

基于机器学习的 SQL 注入漏洞识别方法

DOI:
--
复制
发表时间:
2019
期刊:
International Conference on Automated Software Engineering
影响因子:
--
通讯作者:
Ke Zhang
Ke Zhang
中科院分区:
--
文献类型:
--
作者:
Ke Zhang

文献摘要

被引文献

相似文献

本文提出了一种用于识别PHP代码中SQL注入漏洞的机器学习分类器。使用经典和基于深度学习的机器学习算法来训练和评估分类器模型,使用从源代码文件中提取的输入验证和清理特征。在十倍交叉验证中,使用卷积神经网络(CNN)训练的模型获得了最高的精度(95.4%),而基于多层感知器(MLP)的模型获得了最高的召回率(63.7%)和最高的f-measure(0.746)。
This paper presents a machine learning classifier designed to identify SQL injection vulnerabilities in PHP code. Both classical and deep learning based machine learning algorithms were used to train and evaluate classifier models using input validation and sanitization features extracted from source code files. On ten-fold cross validations a model trained using Convolutional Neural Network(CNN) achieved the highest precision (95.4%), while a model based on Multilayer Perceptron(MLP) achieved the highest recall (63.7%) and the highest f-measure (0.746).