A Machine Learning Based Approach to Identify SQL Injection Vulnerabilities
A Machine Learning Based Approach to Identify SQL Injection Vulnerabilities
复制标题
基于机器学习的 SQL 注入漏洞识别方法
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Ke Zhang
中科院分区:
文献类型:
--
作者:
Ke Zhang
This paper presents a machine learning classifier designed to identify SQL injection vulnerabilities in PHP code. Both classical and deep learning based machine learning algorithms were used to train and evaluate classifier models using input validation and sanitization features extracted from source code files. On ten-fold cross validations a model trained using Convolutional Neural Network(CNN) achieved the highest precision (95.4%), while a model based on Multilayer Perceptron(MLP) achieved the highest recall (63.7%) and the highest f-measure (0.746).