SQL Injection Attacks Detection and Prevention Based on Neuro-Fuzzy Technique

被引:0
|
作者
Nofal, Doaa E. [1 ]
Amer, Abeer A. [2 ]
机构
[1] Alexandria Univ, Inst Grad Studies & Res, Alexandria, Egypt
[2] Sadat Acad Management & Sci, Alexandria, Egypt
来源
PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCED INTELLIGENT SYSTEMS AND INFORMATICS 2019 | 2020年 / 1058卷
关键词
SQL injection attacks; Neuro-fuzzy; ANFIS; FCM; SCG; Web security;
D O I
10.1007/978-3-030-31129-2_66
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Structured Query Language (SQL) injection attack (SQLIA) is one of most famous code injection techniques that threaten web applications, as it could compromise the confidentiality, integrity and availability of the database system of an online application. Whereas other known attacks follow specific patterns, SQLIAs are often unpredictable and demonstrate no specific pattern, which has been greatly problematic to both researchers and developers. Therefore, the detection and prevention of SQLIAs has been a hot topic. This paper proposes a system to provide better results for SQLIA prevention than previous methodologies, taking in consideration the accuracy of the system and its learning capability and flexibility to deal with the issue of uncertainty. The proposed system for SQLIA detection and prevention has been realized on an Adaptive Neuro-Fuzzy Inference System (ANFIS). In addition, the developed system has been enhanced through the use of Fuzzy C-Means (FCM) to deal with the uncertainty problem associated with SQL features. Moreover, Scaled Conjugate Gradient algorithm (SCG) has been utilized to increase the speed of the proposed system drastically. The proposed system has been evaluated using a well-known dataset, and the results show a significant enhancement in the detection and prevention of SQLIAs.
引用
收藏
页码:722 / 738
页数:17
相关论文
共 50 条
  • [21] SQL Injection Detection and Prevention Tools Assessment
    Tajpour, Atefeh
    Heydari, Mohammad Zaman
    Masrom, Maslin
    Ibrahim, Suhaimi
    PROCEEDINGS OF 2010 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 9 (ICCSIT 2010), 2010, : 518 - 522
  • [22] Neuro-Fuzzy Microrobotic System Identification for Haptic Intracellular Injection
    Ghanbari, Ali
    Chen, Xiaoqi
    Wang, Wenhui
    2009 IEEE INTERNATIONAL CONFERENCE ON CONTROL AND AUTOMATION, VOLS 1-3, 2009, : 860 - 866
  • [23] A Neuro-Fuzzy Classifier Based on Evolutionary Algorithms
    Mahboob, Amir Soltany
    Moghaddam, Mohammad Reza Ostadi
    2021 26TH INTERNATIONAL COMPUTER CONFERENCE, COMPUTER SOCIETY OF IRAN (CSICC), 2021,
  • [24] A new method of fuzzy patches construction in Neuro-Fuzzy for malware detection
    Shalaginov, Andrii
    Franke, Katrin
    PROCEEDINGS OF THE 2015 CONFERENCE OF THE INTERNATIONAL FUZZY SYSTEMS ASSOCIATION AND THE EUROPEAN SOCIETY FOR FUZZY LOGIC AND TECHNOLOGY, 2015, 89 : 170 - 177
  • [25] CANDID: Dynamic Candidate Evaluations for Automatic Prevention of SQL Injection Attacks
    Bisht, Prithvi
    Madhusudan, P.
    Venkatakrishnan, V. N.
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (02)
  • [26] Multisignal Histogram-Based Islanding Detection Using Neuro-Fuzzy Algorithm
    Hagh, Mehrdad Tarafdar
    Ghadimi, Noradin
    COMPLEXITY, 2015, 21 (01) : 195 - 205
  • [27] Control of combustion based on neuro-fuzzy model
    Hímer, Z
    Dévényi, G
    Kovács, J
    Kortela, U
    Proceedings of the IASTED International Conference on Applied Simulation and Modelling, 2004, : 13 - 17
  • [28] Cardiac state diagnosis using adaptive neuro-fuzzy technique
    Kannathal, N.
    Lim, C. M.
    Acharya, U. Rajendra
    Sadasivan, P. K.
    MEDICAL ENGINEERING & PHYSICS, 2006, 28 (08) : 809 - 815
  • [29] Adaptive neuro-fuzzy technique for tuning power system stabilizer
    Feilat, E. A.
    Jaroshi, A. M.
    Radaideh, S. M.
    PROCEEDINGS OF THE 41ST INTERNATIONAL UNIVERSITIES POWER ENGINEERING CONFERENCE, VOLS 1 AND 2, 2006, : 170 - +
  • [30] Forecasting the success of a new tourism service by a neuro-fuzzy technique
    Atsalakis, George S.
    Atsalaki, Ioanna G.
    Zopounidis, Constantin
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2018, 268 (02) : 716 - 727