SQL Injection Attacks Detection and Prevention Based on Neuro-Fuzzy Technique

被引:0
|
作者
Nofal, Doaa E. [1 ]
Amer, Abeer A. [2 ]
机构
[1] Alexandria Univ, Inst Grad Studies & Res, Alexandria, Egypt
[2] Sadat Acad Management & Sci, Alexandria, Egypt
来源
PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCED INTELLIGENT SYSTEMS AND INFORMATICS 2019 | 2020年 / 1058卷
关键词
SQL injection attacks; Neuro-fuzzy; ANFIS; FCM; SCG; Web security;
D O I
10.1007/978-3-030-31129-2_66
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Structured Query Language (SQL) injection attack (SQLIA) is one of most famous code injection techniques that threaten web applications, as it could compromise the confidentiality, integrity and availability of the database system of an online application. Whereas other known attacks follow specific patterns, SQLIAs are often unpredictable and demonstrate no specific pattern, which has been greatly problematic to both researchers and developers. Therefore, the detection and prevention of SQLIAs has been a hot topic. This paper proposes a system to provide better results for SQLIA prevention than previous methodologies, taking in consideration the accuracy of the system and its learning capability and flexibility to deal with the issue of uncertainty. The proposed system for SQLIA detection and prevention has been realized on an Adaptive Neuro-Fuzzy Inference System (ANFIS). In addition, the developed system has been enhanced through the use of Fuzzy C-Means (FCM) to deal with the uncertainty problem associated with SQL features. Moreover, Scaled Conjugate Gradient algorithm (SCG) has been utilized to increase the speed of the proposed system drastically. The proposed system has been evaluated using a well-known dataset, and the results show a significant enhancement in the detection and prevention of SQLIAs.
引用
收藏
页码:722 / 738
页数:17
相关论文
共 50 条
  • [1] A Survey on SQL Injection Attacks, Detection and Prevention Techniques
    Kumar, Puspendra
    Pateriya, R. K.
    2012 THIRD INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION & NETWORKING TECHNOLOGIES (ICCCNT), 2012,
  • [2] Adaptive Neuro-Fuzzy Technique for Jamming Detection in VANETs
    Shetty, Shubha R.
    Manjaiah, D. H.
    PROCEEDINGS OF THIRD DOCTORAL SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE, DOSCI 2022, 2023, 479 : 571 - 580
  • [3] A survey on SQL injection attacks, detection and prevention techniques – a tertiary study
    Hallo M.
    Suntaxi G.
    International Journal of Security and Networks, 2022, 17 (03) : 193 - 202
  • [4] A neuro-fuzzy technique for document binarisation
    Papamarkos, N
    NEURAL COMPUTING & APPLICATIONS, 2003, 12 (3-4) : 190 - 199
  • [5] Network Intrusion Detection Based on Neuro-Fuzzy Classification
    Toosi, Adel Nadjaran
    Kahani, Mohsen
    Monsefi, Reza
    2006 INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS (ICOCI 2006), 2006, : 345 - +
  • [6] A neuro-fuzzy technique for document binarisation
    Nikos Papamarkos
    Neural Computing & Applications, 2003, 12 : 190 - 199
  • [7] Classification of SQL Injection Attacks Using Fuzzy Tainting
    Khanna, Surya
    Verma, A. K.
    PROGRESS IN INTELLIGENT COMPUTING TECHNIQUES: THEORY, PRACTICE, AND APPLICATIONS, VOL 1, 2018, 518 : 463 - 469
  • [8] An Efficient Technique for Detection and Prevention of SQL Injection Attack using ASCII Based String Matching
    Balasundaram, Indrani
    Ramaraj, E.
    INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY AND SYSTEM DESIGN 2011, 2012, 30 : 183 - 190
  • [9] Detection of SQL Injection Attacks by Removing the Parameter Values of SQL Query
    Katole, Rajashree A.
    Sherekar, Swati S.
    Thakare, Vilas M.
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON INVENTIVE SYSTEMS AND CONTROL (ICISC 2018), 2018, : 736 - 741
  • [10] Detection of distributed denial of service attacks using an ensemble of adaptive and hybrid neuro-fuzzy systems
    Kumar, P. Arun Raj
    Selvakumar, S.
    COMPUTER COMMUNICATIONS, 2013, 36 (03) : 303 - 319