Evaluating CNN Effectiveness in SQL Injection Attack Detection

Clicks: 1
ID: 312958
2024
Article Quality & Performance Metrics
Overall Quality
Not rated
Combines reader engagement with the AI quality analysis. This article has not been analysed, so there is no overall score — reader engagement is measured and shown alongside.
AI Quality Assessment
Not analyzed
Readership in this journal

Ranked #391 of 705 articles by views in Journal of Computing & Biomedical Informatics

Most read Least read

Bar heights use a square-root scale. Only the 120 most-read articles are drawn; the journal has 705 in total.

Mint this article as an NFT
Not yet minted

Create a permanent, verifiable on-chain record of this article on the Scimatic Network. The NFT is held in your Journament account, and you can withdraw it to your own wallet at any time.

5 SUSD one-off · no wallet required
Abstract
SQL injection attacks are among the most prominent threats against Web application security, intended to illegitimately access sensitive information by exploiting related vulnerabilities. Their detection with traditional rule-based approaches is futile in view of this evolving nature and complexity of SQL Injection Attack (SQLIA). This paper proposes a new approach towards detecting SQLIA using Convolutional Neural Networks, one of the deep learning techniques very famous for its capability of automatically learning intricate patterns and representations from large-scale datasets. We focus on leveraging this strength of CNNs while working on the structure and semantics of SQL queries to help in differentiating malicious and benign inputs. In this paper, we describe a detailed method-ology that includes data preprocessing, feature extraction, model training, and evaluation. In this paper, we propose a CNN model trained and tested using a large dataset containing 109,520 SQL queries with an accuracy of 97.41%. Further, we have tested the efficiency of the model with the help of precision, recall, and F1-score, and it turned out to be effective for the identification and classifications of SQLIA properly. The model showed high precision, 96.50%, and high recall, 99.00%, which gives it the capability to reduce false positives and false negatives. The balanced F1-score was 97.00%, thereby confirming that this model performed well in detecting and classifying SQLIAs. These results may indicate that deep learning techniques, and particularly CNNs, have some potential to be very useful in enhancing web application security by providing a robust, adaptive solution for mitigating risks caused by SQL injection attacks.
Reference Key
imported_1777058066_69ebc112230b9 Use this key to autocite in the manuscript while using SciMatic Manuscript Manager or Thesis Manager
Authors Mudassar Rehman
Journal Journal of Computing & Biomedical Informatics
Year 2024
DOI
DOI not found
URL
Keywords Keywords not found

Citations

No citations found. To add a citation, contact the admin at info@scimatic.org

No comments yet. Be the first to comment on this article.