An Sql Injection Detection Model Using Chi-Square with Classification Techniques

被引:3
作者
Adebiyi, Marion Olubunmi [1 ]
Arowolo, Micheal Olaolu [1 ]
Archibong, Goodnews Ime [1 ]
Mshelia, Moses Damilola [1 ]
Adebiyi, Ayodele Ariyo [1 ]
机构
[1] Landmark Univ, Dept Comp Sci, Omu Aran, Nigeria
来源
INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021) | 2021年
关键词
SQL Injection; Chi-Square; Naive Bayes; Decision Tree; KNN;
D O I
10.1109/ICECET52533.2021.9698771
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
SQL Injection attacks is a common threat to web applications that utilizes poor input validation to implement attack on a target database. It is becoming a very serious problem in web application as successful leads to loss of integrity and confidentiality and this makes it a very sensitive issue of software security. This study gives a review on SQL Injection detection and prevention techniques using machine learning classifiers. Machine Learning approach has been found to be profound for SQLIA mitigation, which is implemented through defensive coding approach. An experimental analysis was performed to evaluate the performance of the learning classification algorithms to choose the best algorithm. It is imperative to note that a good number of the evaluated techniques were able to detect and prevent the SQLIA based on the KDD Test dataset. From the findings, Naive Bayes had the minimum Accuracy 80.01%, Sensitivity as well as Specificity while Decision Tree had the highest Accuracy 98.11%, Sensitivity and Specificity and therefore was chosen as the best classifier for SQLIA detection and prevention. Therefore, beyond Accuracy, other performance evaluation metrics are critical for optimal algorithm selection for predictive analytics.
引用
收藏
页码:289 / 296
页数:8
相关论文
共 50 条
  • [41] Using Classification Techniques for Creation of Predictive Intrusion Detection Model
    Almutairi, Abdulrazaq
    Parish, David
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 223 - 228
  • [42] Shielding Against SQL Injection Attacks Using ADMIRE Model
    Madan, Sushila
    Madan, Supriya
    2009 1ST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS(CICSYN 2009), 2009, : 314 - +
  • [43] A Novel Study: GAN-Based Minority Class Balancing and Machine-Learning-Based Network Intruder Detection Using Chi-Square Feature Selection
    Alabrah, Amerah
    APPLIED SCIENCES-BASEL, 2022, 12 (22):
  • [44] CHIFISH: a computer program testing for genetic heterogeneity at multiple loci using chi-square and Fisher's exact test
    Ryman, N
    MOLECULAR ECOLOGY NOTES, 2006, 6 (01): : 285 - 287
  • [45] SQL Injection Attack Detection Using Fingerprints and Pattern Matching Technique
    Appiah, Benjamin
    Opoku-Mensah, Eugene
    Qin, Zhiguang
    PROCEEDINGS OF 2017 8TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2017), 2017, : 583 - 587
  • [46] Personalised news filtering and recommendation system using Chi-square statistics-based K-nearest neighbour (2SB-KNN) model
    Adeniyi, D. A.
    Wei, Z.
    Yang, Y.
    ENTERPRISE INFORMATION SYSTEMS, 2017, 11 (09) : 1283 - 1316
  • [47] Multi-Source Data Analysis and Evaluation of Machine Learning Techniques for SQL Injection Detection
    Ross, Kevin
    Moh, Melody
    Moh, Teng-Sheng
    Yao, Jason
    ACMSE '18: PROCEEDINGS OF THE ACMSE 2018 CONFERENCE, 2018,
  • [48] Performance assessment of artificial neural network using chi-square and backward elimination feature selection methods for landslide susceptibility analysis
    Pham, Binh Thai
    Van Dao, Dong
    Acharya, Tri Dev
    Van Phong, Tran
    Costache, Romulus
    Van Le, Hiep
    Nguyen, Hanh Bich Thi
    Prakash, Indra
    ENVIRONMENTAL EARTH SCIENCES, 2021, 80 (20)
  • [49] Performance assessment of artificial neural network using chi-square and backward elimination feature selection methods for landslide susceptibility analysis
    Binh Thai Pham
    Dong Van Dao
    Tri Dev Acharya
    Tran Van Phong
    Romulus Costache
    Hiep Van Le
    Hanh Bich Thi Nguyen
    Indra Prakash
    Environmental Earth Sciences, 2021, 80
  • [50] Detecting SQL Injection On Web Application Using Deep Learning Techniques: A Systematic Literature Review
    Muslihi, Muhammad Takdir
    Alghazzawi, Daniyal
    2020 THIRD INTERNATIONAL CONFERENCE ON VOCATIONAL EDUCATION AND ELECTRICAL ENGINEERING (ICVEE): STRENGTHENING THE FRAMEWORK OF SOCIETY 5.0 THROUGH INNOVATIONS IN EDUCATION, ELECTRICAL, ENGINEERING AND INFORMATICS ENGINEERING, 2020,