<p>SQL injection (SQLi) continues to be a serious threat to the database-driven web and mobile applications. The current detection techniques are mainly based on rule-based reasoning or manually designed features, which are less effective to obfuscated and novel payloads. While deep-learning methods can learn complex representations, many studies evaluate structural or semantic information separately, making it difficult to determine their individual and complementary contributions. In this work, the authors propose a hybrid SQLi detection framework by exploiting structural features at the payload level and contextual embeddings generated by RoBERTa. The structural representation encodes syntactic, statistical, and attack-related features, while the semantic representation models contextual relations in SQL payloads. The extracted structural, RoBERTa-based, and combined features have been evaluated separately with decision tree, naive Bayes, support vector machine, random forest, deep multilayer perception, and long short-term memory classifiers using k-fold cross-validation. The best configuration achieved accuracy, recall, F1-score and AUC of 99.06%, 99.74%, 98.71% and 99.52%, respectively. The results show that for the evaluated datasets and experimental settings, the combined usage of structural and contextual information provides a more discriminative representation for SQLi detection than using one of the representations only. Therefore, the proposed framework offers a systematic ground to investigate the complementary contribution of structural and transformer-based semantic features for SQLi classification.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing SQL injection detection via hybrid structural and transformer-based semantic feature extraction

  • Bahman Arasteh,
  • Yashar Niyayesh,
  • Ali Mohammadjafari,
  • Huseyin Kusetogullari,
  • Keyvan Arasteh

摘要

SQL injection (SQLi) continues to be a serious threat to the database-driven web and mobile applications. The current detection techniques are mainly based on rule-based reasoning or manually designed features, which are less effective to obfuscated and novel payloads. While deep-learning methods can learn complex representations, many studies evaluate structural or semantic information separately, making it difficult to determine their individual and complementary contributions. In this work, the authors propose a hybrid SQLi detection framework by exploiting structural features at the payload level and contextual embeddings generated by RoBERTa. The structural representation encodes syntactic, statistical, and attack-related features, while the semantic representation models contextual relations in SQL payloads. The extracted structural, RoBERTa-based, and combined features have been evaluated separately with decision tree, naive Bayes, support vector machine, random forest, deep multilayer perception, and long short-term memory classifiers using k-fold cross-validation. The best configuration achieved accuracy, recall, F1-score and AUC of 99.06%, 99.74%, 98.71% and 99.52%, respectively. The results show that for the evaluated datasets and experimental settings, the combined usage of structural and contextual information provides a more discriminative representation for SQLi detection than using one of the representations only. Therefore, the proposed framework offers a systematic ground to investigate the complementary contribution of structural and transformer-based semantic features for SQLi classification.