SQL Injection Detection Based on Deep Belief Network

被引:7
|
作者
Zhang, Huafeng [1 ]
Zhao, Bo [1 ]
Yuan, Hui [2 ]
Zhao, Jinxiong [1 ]
Yan, Xiaobin [1 ]
Li, Fangjun [1 ]
机构
[1] State Grid Gansu Elect Power Co, Lanzhou, Peoples R China
[2] State Grid Gansu Elect Power Res Inst, Lanzhou, Peoples R China
来源
PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE2019) | 2019年
关键词
Cyber Security; SQL Injection; Deep Learning; Deep Belief Network (DBN);
D O I
10.1145/3331453.3361280
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
At present, the ways for detecting SQL injection attacks include pre-compilation of SQL statements, filtering user input at the WEB layer to prevent SQL injection, such as filtering global parameters with Filter, strictly restricting the operation authority of the database, and trying to satisfy all. The lowest permissions for the operation, etc. The detection method for the SQL injection attack is mainly to analyze the incoming parameters to determine whether an illegal parameter is passed in. However, due to the poor real-time performance of the analyzed traffic content and the accuracy, the false positive rate is not ideal. Therefore, this paper proposes a deep learning-based approach to find SQL injection aggression. It does not need to analyze and extract all the content. It only needs to find out the features needed by the model. Entering these features into the model that is trained in advance can detect SQL injection attacks traffic in real time. This paper use deep learning to identify SQL injection attacks in network traffic. We select the target features according to the attack characteristics of the SQL injection attack and get request from url or post packet as train data; use the deep belief network (DBN) model to train the selected features and the collected sample data, and finally get an identifiable SQL Injection attack model. Finally find a best model for Detecting SQL injection, and achieve online and real-time detection.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Speech Separation based on Deep Belief Network
    Wu Haijia
    Zhang Xiongwei
    Zhang Liangliang
    Zou Xia
    PROCEEDINGS OF THE 2015 INTERNATIONAL INDUSTRIAL INFORMATICS AND COMPUTER ENGINEERING CONFERENCE, 2015, : 1486 - 1493
  • [22] AE-Net: Novel Autoencoder-Based Deep Features for SQL Injection Attack Detection
    Thalji, Nisrean
    Raza, Ali
    Islam, Mohammad Shariful
    Samee, Nagwan Abdel
    Jamjoom, Mona M.
    IEEE ACCESS, 2023, 11 : 135507 - 135516
  • [23] Event Recognition Based on Deep Belief Network
    Zhang Y.-J.
    Liu Z.-T.
    Zhou W.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2017, 45 (06): : 1415 - 1423
  • [24] Analysis of SQL Injection Based on Petri Net in Wireless Network
    Wang, Yi-Chuan
    Zhang, Gui-Ling
    Zhang, Ya-Ling
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2023, 39 (01) : 167 - 181
  • [25] An optimization-based deep belief network for the detection of phishing e-mails
    Arshey, M.
    Viji, Angel K. S.
    DATA TECHNOLOGIES AND APPLICATIONS, 2020, 54 (04) : 529 - 549
  • [26] Moth Monarch Optimization-Based Deep Belief Network in Deception Detection System
    Srivastava, Nidhi
    Dubey, Sipi
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2020, 45 (01):
  • [27] Computational Linguistics with Optimal Deep Belief Network Based Irony Detection in Social Media
    Hamza, Manar Ahmed
    Alshahrani, Hala J.
    Hassan, Abdulkhaleq Q. A.
    Gaddah, Abdulbaset
    Allheeib, Nasser
    Alsaif, Suleiman Ali
    Al-onazi, Badriyya B.
    Mohsen, Heba
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 75 (02): : 4137 - 4154
  • [28] Neural network based single index evaluation for SQL injection attack detection in health care data
    Nagabhooshanam N.
    ganapathy N.B.S.
    Ravindra Murthy C.
    Mohammed Saleh A.A.
    CosioBorda R.F.
    Measurement: Sensors, 2023, 27
  • [29] Moth Monarch Optimization-Based Deep Belief Network in Deception Detection System
    NIDHI SRIVASTAVA
    SIPI DUBEY
    Sādhanā, 2020, 45
  • [30] SQL Injection Attack Detection Framework Based on HTTP Traffic
    Zhu, Zhongdong
    Jia, Shilin
    Li, Jishuai
    Qin, Sujuan
    Guo, Hui
    PROCEEDINGS OF ACM TURING AWARD CELEBRATION CONFERENCE, ACM TURC 2021, 2021, : 179 - 185