Dr Naghmeh Moradpoor N.Moradpoor@napier.ac.uk
Associate Professor
Thousands of organisations store important and confidential information related to them, their customers, and their business partners in databases all across the world. The stored data ranges from less sensitive (e.g. first name, last name, date of birth) to more sensitive data (e.g. password, pin code, and credit card information). Losing data, disclosing confidential information or even changing the value of data are the severe damages that Structured Query Language injection (SQLi) attack can cause on a given database. It is a code injection technique where malicious SQL statements are inserted into a given SQL database by simply using a web browser. In this paper, we propose an effective pattern recognition neural network model for detection and classification of SQLi attacks. The proposed model is built from three main elements of: a Uniform Resource Locator (URL) generator in order to generate thousands of malicious and benign URLs, a URL classifier in order to: 1) classify each generated URL to either a benign URL or a malicious URL and 2) classify the malicious URLs into different SQLi attack categories, and a NN model in order to: 1) detect either a given URL is a malicious URL or a benign URL and 2) identify the type of SQLi attack for each malicious URL. The model is first trained and then evaluated by employing thousands of benign and malicious URLs. The results of the experiments are presented in order to demonstrate the effectiveness of the proposed approach.
Moradpoor Sheykhkanloo, N. (2015). A Pattern Recognition Neural Network Model for Detection and Classification of SQL Injection Attacks. International Journal of Computer, Electrical, Automation, Control and Information Engineering, 9(6), 1443-1453
Journal Article Type | Article |
---|---|
Acceptance Date | Feb 1, 2015 |
Publication Date | Nov 1, 2015 |
Deposit Date | Feb 28, 2017 |
Publicly Available Date | Feb 28, 2017 |
Journal | International Journal of Computer, Electrical, Automation, Control and Information Engineering |
Print ISSN | 2010-376X |
Publisher | World Academy of Science, Engineering and Technology |
Peer Reviewed | Peer Reviewed |
Volume | 9 |
Issue | 6 |
Pages | 1443-1453 |
Keywords | Neural Networks, pattern recognition, SQL injection; attacks, SQL injection attack classification, SQL injection attack; detection |
Public URL | http://researchrepository.napier.ac.uk/Output/690348 |
A Pattern Recognition Neural Network Model for Detection and Classification of SQL Injection Attacks
(325 Kb)
PDF
A Proposed Continuous Facial Recognition Framework for Adaptive Environmental Detection
(2025)
Presentation / Conference Contribution
Binius Zero-Knowledge Proofs Meet Multi-Layer Bloom Filters: A Secure and Efficient Protocol for Federated Learning in Autonomous Vehicle Networks
(2025)
Presentation / Conference Contribution
Ransomware: Analysis and Evaluation of Live Forensic Techniques and the Impact on Linux Based IoT Systems
(2025)
Presentation / Conference Contribution
ARSecure: A Novel End-to-End Encryption Messaging System Using Augmented Reality
(2025)
Presentation / Conference Contribution
About Edinburgh Napier Research Repository
Administrator e-mail: repository@napier.ac.uk
This application uses the following open-source libraries:
Apache License Version 2.0 (http://www.apache.org/licenses/)
Apache License Version 2.0 (http://www.apache.org/licenses/)
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search