arrow
返回

SQL Injection Attack classification through the feature extraction of SQL query strings using a Gap-Weighted String Subsequence Kernel

delete2018-06-01
delete32
delete
OA
AI
P
Paul R. McWhirter
K
Kashif Kifayat *
Q
Qi Shi
B
Bob Askwith
DOI:10.1016/j.jisa.2018.04.001delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
SQL Injection Attacks are one of the most common methods behind data security breaches. Previous research has attempted to produce viable detection solutions in order to filter SQL Injection Attacks from regular queries. Unfortunately it has proven to be a challenging problem with many solutions suffering from disadvantages such as being unable to process in real time as a preventative solution, a lack of adaptability to differing types of attack and the requirement for access to difficult-to-obtain information about the source application. This paper presents a novel solution of classifying SQL queries purely on the features of the initial query string. A Gap-Weighted String Subsequence Kernel algorithm is implemented to identify subsequences of shared characters between query strings for the output of a similarity metric. Finally a Support Vector Machine is trained on the similarity metrics between known query strings which are then used to classify unknown test queries. By gathering all feature data from the query strings, additional information from the source application is not required. The probabilistic nature of the learned models allows the solution to adapt to new threats whilst in operation. The proposed solution is evaluated using a number of test datasets derived from the Amnesia testbed datasets. The demonstration software achieved 97.07% accuracy for Select type queries and 92.48% accuracy for Insert type queries. This limited success rate is due to unsanitized quotation marks within legitimate inputs confusing the feature extraction. Using a test dataset that denies legitimate queries the use of unsanitized quotation marks, the Select and Insert query accuracy rose. (C) 2018 Elsevier Ltd. All rights reserved.
Keyword:
Intrusion detection
SQL Injection Attacks
Data mining
String Subsequence Kernel
Support vector machine
Supervised learning
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
1.9K
被引数:
4.9K

机构

L
Liverpool John Moores University
学者数:
5.7K
论文数: 6.5K
被引数: 1.1W
引用论文

引用论文

SQLiGoT: Detecting SQL injection attacks using graph of tokens and SVM
err2016-07-01
err51
PREAI
errKar, Debabrata; Panigrahi, Suvasini; Sundararajan, Srikanth
err分享
err收藏
Me and My Group: Cultural Status Can Disrupt Cognitive Consistency
err2005-08-01
err0
PREAI
errKristin A. Lane; Jason P. Mitchell; Mahzarin R. Banaji
err分享
err收藏
err分享
err收藏
err分享
err收藏
没有更多内容