An Sql Injection Detection Model Using Chi-Square with Classification Techniques

被引:3
作者
Adebiyi, Marion Olubunmi [1 ]
Arowolo, Micheal Olaolu [1 ]
Archibong, Goodnews Ime [1 ]
Mshelia, Moses Damilola [1 ]
Adebiyi, Ayodele Ariyo [1 ]
机构
[1] Landmark Univ, Dept Comp Sci, Omu Aran, Nigeria
来源
INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021) | 2021年
关键词
SQL Injection; Chi-Square; Naive Bayes; Decision Tree; KNN;
D O I
10.1109/ICECET52533.2021.9698771
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
SQL Injection attacks is a common threat to web applications that utilizes poor input validation to implement attack on a target database. It is becoming a very serious problem in web application as successful leads to loss of integrity and confidentiality and this makes it a very sensitive issue of software security. This study gives a review on SQL Injection detection and prevention techniques using machine learning classifiers. Machine Learning approach has been found to be profound for SQLIA mitigation, which is implemented through defensive coding approach. An experimental analysis was performed to evaluate the performance of the learning classification algorithms to choose the best algorithm. It is imperative to note that a good number of the evaluated techniques were able to detect and prevent the SQLIA based on the KDD Test dataset. From the findings, Naive Bayes had the minimum Accuracy 80.01%, Sensitivity as well as Specificity while Decision Tree had the highest Accuracy 98.11%, Sensitivity and Specificity and therefore was chosen as the best classifier for SQLIA detection and prevention. Therefore, beyond Accuracy, other performance evaluation metrics are critical for optimal algorithm selection for predictive analytics.
引用
收藏
页码:289 / 296
页数:8
相关论文
共 50 条
  • [31] Classification of SQL Injection Attacks Using Fuzzy Tainting
    Khanna, Surya
    Verma, A. K.
    PROGRESS IN INTELLIGENT COMPUTING TECHNIQUES: THEORY, PRACTICE, AND APPLICATIONS, VOL 1, 2018, 518 : 463 - 469
  • [32] CoVID-19 symptoms analysis of deceased and recovered cases using Chi-square test
    Al-Najjar, D.
    Al-Najjar, H.
    Al-Rousan, N.
    EUROPEAN REVIEW FOR MEDICAL AND PHARMACOLOGICAL SCIENCES, 2020, 24 (21) : 11428 - 11431
  • [33] SCADA intrusion detection scheme exploiting the fusion of modified decision tree and Chi-square feature selection
    Ahakonye, Love Allen Chijioke
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae-Min
    Kim, Dong-Seong
    INTERNET OF THINGS, 2023, 21
  • [34] Application of Hidden Markov Model in SQL Injection Detection
    Li, Peng
    Liu, Lei
    Xu, Jing
    Yang, Hongji
    Yuan, Liying
    Guo, Chenkai
    Ji, Xiujuan
    2017 IEEE 41ST ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 2, 2017, : 578 - 583
  • [35] Detection Model for SQL Injection Attack: An Approach for Preventing a Web Application from the SQL Injection Attack
    Buja, Geogiana
    Bin Abd Jalil, Kamarularifin
    Ali, Fakariah Bt Hj Mohd
    Rahman, Teh Faradilla Abdul
    2014 IEEE SYMPOSIUM ON COMPUTER APPLICATIONS AND INDUSTRIAL ELECTRONICS (ISCAIE), 2014,
  • [36] Intrusion Detection Model Using Chi Square Feature Selection and Modified Naive Bayes Classifier
    Thaseen, I. Sumaiya
    Kumar, Ch. Aswani
    PROCEEDINGS OF THE 3RD INTERNATIONAL SYMPOSIUM ON BIG DATA AND CLOUD COMPUTING CHALLENGES (ISBCC - 16'), 2016, 49 : 81 - 91
  • [37] Smart Cities-Based Improving Atmospheric Particulate Matters Prediction Using Chi-Square Feature Selection Methods by Employing Machine Learning Techniques
    Mengash, Hanan Abdullah
    Hussain, Lal
    Mahgoub, Hany
    Al-Qarafi, A.
    Nour, Mohamed K.
    Marzouk, Radwa
    Qureshi, Shahzad Ahmad
    Hilal, Anwer Mustafa
    APPLIED ARTIFICIAL INTELLIGENCE, 2022, 36 (01)
  • [38] Evaluating Mutual Information and Chi-Square Metrics in Text Features Selection Process: A Study Case Applied to the Text Classification in PubMed
    Parraga-Valle, Jose
    Garcia-Bermudez, Rodolfo
    Rojas, Fernando
    Torres-Moran, Christian
    Simon-Cuevas, Alfredo
    BIOINFORMATICS AND BIOMEDICAL ENGINEERING (IWBBIO 2020), 2020, 12108 : 636 - 646
  • [39] Detection and Prevention of SQL Injection Attacks Using Semantic Equivalence
    Narayanan, Sandeep Nair
    Pais, Alwyn Roshan
    Mohandas, Radhesh
    COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 103 - 112
  • [40] Detection of SQL Injection Using a Genetic Fuzzy Classifier System
    Basta, Christine
    Elfatatry, Ahmed
    Darwish, Saad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (06) : 129 - 137