SQL injection (SQLi) remains a critical cybersecurity threat, exploiting vulnerabilities in web applications to manipulate databases. Recognized as a significant risk, SQLi involves attackers using malicious SQL code via user inputs like form fields or URL parameters. Traditional detection methods, based on static patterns, often fail to capture the complexity of these attacks. To address this, we propose a novel staging SQLi detection approach integrating feature-based model-stacking, which combines naive machine-learning-based NLP techniques with advanced transformer-based NLP methods for improved accuracy and efficiency. This paper presents a comprehensive evaluation on two SQLi datasets, demonstrating our approach’s effectiveness in enhancing the security of web applications and databases. Key contributions include a hybrid detection approach, a novel performance metric, and a detailed comparison of various detection methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Staging with Feature-Based Model-Stacking for Rapid SQL Injection Detection

  • Yangyong Liu

摘要

SQL injection (SQLi) remains a critical cybersecurity threat, exploiting vulnerabilities in web applications to manipulate databases. Recognized as a significant risk, SQLi involves attackers using malicious SQL code via user inputs like form fields or URL parameters. Traditional detection methods, based on static patterns, often fail to capture the complexity of these attacks. To address this, we propose a novel staging SQLi detection approach integrating feature-based model-stacking, which combines naive machine-learning-based NLP techniques with advanced transformer-based NLP methods for improved accuracy and efficiency. This paper presents a comprehensive evaluation on two SQLi datasets, demonstrating our approach’s effectiveness in enhancing the security of web applications and databases. Key contributions include a hybrid detection approach, a novel performance metric, and a detailed comparison of various detection methods.