review of SQLI detection strategies using machine learning

review of SQLI detection strategies using machine learning
复制标题

使用机器学习回顾 SQLI 检测策略

DOI:
--
复制
发表时间:
2022
期刊:
International Journal of Health Sciences
影响因子:
--
通讯作者:
Subir Gupta
Subir Gupta
中科院分区:
--
文献类型:
--
作者:
B. Mondal;Abhijit Banerjee;Subir Gupta

文献摘要

被引文献

相似文献

通过互联网提供材料的各种平台和网络应用程序正变得越来越普遍。基于Web的技术接受并存储来自用户的敏感信息。由于它们的互联网连接,这些系统及其链接的数据库容易受到各种信息安全漏洞的攻击。最危险的威胁是拒绝服务(DoS)和SQL注入攻击。在基于Web的系统中,SQL注入攻击位居榜首。在这种类型的攻击中,攻击者会窃取可能会损害公司或企业的敏感和机密信息。视情况而定,该公司可能会遭受财务损失,私人信息被披露,其股票市值可能会缩水。该工作使用基于机器学习的分类器,如MLP、支持向量机、Logistic回归、朴素贝叶斯和决策树来识别和检测SQL注入攻击。对于SQLI数据集学习策略,我们使用混淆矩阵、F1分数和Log Lost检查了所有五种算法。我们讨论了提出的基于人工智能的SQLI技术的优点和缺点。最后,我们谈到在未来几年通过更多的研究使SQLI充分发挥其潜力。
Various platforms and web apps to deliver material via the Internet are becoming more widespread. Web-based technologies accept and store sensitive information from users. Because of their Internet connectivity, these systems and the databases they link to are vulnerable to various information security vulnerabilities. The most dangerous threats are denial of service (DoS) and SQL injection assaults. SQL Injection attacks are at the top of the list for web-based systems. In this type of attack, the perpetrator will take sensitive and classified information that might hurt a firm or enterprise. Depending on the conditions, the corporation may incur financial losses, have private information disclosed, and have its stock market value drop. This work uses machine learning-based classifiers such as MLP, Support Vector Machine, Logistic Regression, Naive Bayes, and Decision Tree to identify and detect SQL Injection attacks. For the SQLI dataset learning strategies, we examined all five algorithms using the Confusion Matrix, F1 Score, and Log Loss. We discuss the benefits and drawbacks of the proposed AI-based SQLI techniques. Finally, we talk about making SQLI reach its full potential through more research in the coming years.