An Sql Injection Detection Model Using Chi-Square with Classification Techniques

被引:3
作者
Adebiyi, Marion Olubunmi [1 ]
Arowolo, Micheal Olaolu [1 ]
Archibong, Goodnews Ime [1 ]
Mshelia, Moses Damilola [1 ]
Adebiyi, Ayodele Ariyo [1 ]
机构
[1] Landmark Univ, Dept Comp Sci, Omu Aran, Nigeria
来源
INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021) | 2021年
关键词
SQL Injection; Chi-Square; Naive Bayes; Decision Tree; KNN;
D O I
10.1109/ICECET52533.2021.9698771
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
SQL Injection attacks is a common threat to web applications that utilizes poor input validation to implement attack on a target database. It is becoming a very serious problem in web application as successful leads to loss of integrity and confidentiality and this makes it a very sensitive issue of software security. This study gives a review on SQL Injection detection and prevention techniques using machine learning classifiers. Machine Learning approach has been found to be profound for SQLIA mitigation, which is implemented through defensive coding approach. An experimental analysis was performed to evaluate the performance of the learning classification algorithms to choose the best algorithm. It is imperative to note that a good number of the evaluated techniques were able to detect and prevent the SQLIA based on the KDD Test dataset. From the findings, Naive Bayes had the minimum Accuracy 80.01%, Sensitivity as well as Specificity while Decision Tree had the highest Accuracy 98.11%, Sensitivity and Specificity and therefore was chosen as the best classifier for SQLIA detection and prevention. Therefore, beyond Accuracy, other performance evaluation metrics are critical for optimal algorithm selection for predictive analytics.
引用
收藏
页码:289 / 296
页数:8
相关论文
共 50 条
  • [21] Ensemble Feature Subset Selection: Integration of Symmetric Uncertainty and Chi-Square techniques with RReliefF
    Sumant A.S.
    Patil D.
    Journal of The Institution of Engineers (India): Series B, 2022, 103 (03) : 831 - 844
  • [22] Chi-Square and PCA Based Feature Selection for Diabetes Detection with Ensemble Classifier
    Rupapara, Vaibhav
    Rustam, Furqan
    Ishaq, Abid
    Lee, Ernesto
    Ashraf, Imran
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2023, 36 (02) : 1931 - 1949
  • [23] Detection of SQL Injection Attacks using Hidden Markov Model
    Kar, Debabrata
    Agarwal, Khushboo
    Sahoo, Ajit Kumar
    Panigrahi, Suvasini
    PROCEEDINGS OF 2ND IEEE INTERNATIONAL CONFERENCE ON ENGINEERING & TECHNOLOGY ICETECH-2016, 2016, : 1 - 6
  • [24] Analysis and implementation of SQL injection attack and countermeasures using SQL injection prevention techniques
    Jesudoss, A.
    Mercy, Theresa M.
    Christy, A.
    Maheswari, M.
    Selvi, M.
    Ulagamuthalvi, V
    INTERNATIONAL JOURNAL OF ENGINEERING SYSTEMS MODELLING AND SIMULATION, 2022, 13 (04) : 262 - 267
  • [25] A Chi-Square Methodology Applied in Deviations Control of Project Plan to support the RIMAM model
    Montini, Denis Avila
    Battaglia, Danilo
    Matuck, Gustavo Ravanhani
    da Cunha, Adilson Marques
    Vieira Dias, Luiz Alberto
    Montini, Alessandra Avila
    2014 11TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS (ITNG), 2014, : 9 - 14
  • [26] Generation of robust phonetic set and decision tree for Mandarin using chi-square testing
    Chen, YJ
    Wu, CH
    Chiu, YH
    Liao, HC
    SPEECH COMMUNICATION, 2002, 38 (3-4) : 349 - 364
  • [27] An Improved Ensemble-Based Cardiovascular Disease Detection System with Chi-Square Feature Selection
    Korial, Ayad E.
    Gorial, Ivan Isho
    Humaidi, Amjad J.
    COMPUTERS, 2024, 13 (06)
  • [28] LsSQLIDP : Literature survey on SQL injection detection and prevention techniques
    Varshney, Karishma
    Ujjwal, R. L.
    JOURNAL OF STATISTICS & MANAGEMENT SYSTEMS, 2019, 22 (02) : 257 - 269
  • [29] A systematic review of detection and prevention techniques of SQL injection attacks
    Nasereddin, Mohammed
    ALKhamaiseh, Ashaar
    Qasaimeh, Malik
    Al-Qassas, Raad
    INFORMATION SECURITY JOURNAL, 2023, 32 (04): : 252 - 265
  • [30] SQL Injection Attack Detection using ResNet
    Sangeeta
    Nagasundari, S.
    Honnavali, Prasad B.
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,