Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Securing Web Applications Against Payload Attacks Using Deep Learning-Based Model

Sako, DJS; Nnodi, Joy T; Igiri, CG

Abstract

Web applications are critical to modern systems but are increasingly targeted by payload attacks, where malicious data is injected to exploit vulnerabilities, steal information, or disrupt operations. SQL injection and cross-site scripting (XXS) attacks are two of the most common types of attacks that can compromise web applications. This paper proposes a model for the detection of SQL and XXS attacks, which aims to enhance the security of web applications and prevent potential damages. The methodology involves three main stages: data preprocessing, feature extraction, and model training and classification. First, a dataset consisting of structured queries, which comprise of both safe and unsafe (XSS and SQL injection attack) queries, is collected and preprocessed. Then, features are extracted from the dataset using statistical and machine learning techniques, which are used to train and test LSTM-based classification model. Finally, the model is evaluated using different performance metrics, including accuracy, precision, recall, and F1-score. The results showed that the proposed model can effectively detect SQL and XXS attacks with a high accuracy rate of 98%, and can also handle different attack scenarios with low false positive rates.

Keywords

Payload attacksweb applicationsSQL InjectionCross-Site ScriptingLSTM

References

Abirami J., Devakunchari R., and Valliyammai C. (2015). A top web security vulnerability SQL injection attack — Survey, Seventh International Conference on Advanced Computing (ICoAC). Alwan, Z. S., & Younis, M. F. (2017). Detection and prevention of SQL injection attack: a survey. International Journal of Computer Science and Mobile Computing, 6(8), 5-17. Banach, Z. (2023). OWASP Top 10 2017 web application vulnerabilities. Invicti. Accessed 10- dec-2024 from https://www.invicti.com/blog/web-security/owasp-top-10/ Ding C., Qiseng Y., Chunwang W., and Jun Z. (2021). SQL Injection Attack Detection and Prevention Techniques Using Deep Learning. Journal of Physics: Conference Series. 1757, doi:10.1088/1742-6596/1757/1/012055. Hassan, M. M., Ahmad, R. B., & Ghosh, T. (2021). SQL injection vulnerability detection using deep learning: a feature-based approach. Indonesian Journal of Electrical Engineering and Informatics (IJEEI), 9(3), 702-718. http://dx.doi.org/10.52549/.v9i3.3131 Hochreiter S. and Schmidhuber J. (2017). LSTM can solve hard long time lag problems, Adv. Neural Inf. Process. Syst., 473–479. Jai P. S. (2016). Analysis of SQL Injection Detection Techniques, Theoretical and Applied Informatics (TAAI), 28(1-2), 37—55. Jothi, K. R., Pandey, N., Beriwal, P., and Amarajan, A. (2021). An efficient SQL injection detection system using deep learning. In 2021 International conference on computational intelligence and knowledge economy (ICCIKE), 442-445 Kascheev, S. and Olenchikova, T.(2020). The detecting cross-site scripting (XSS) using machine learning methods. In Proceedings of the 2020 Global Smart Industry Conference (GloSIC), Chelyabinsk, 265–270. Kevin Z. (2019). A Machine Learning based Approach to Identify SQL Injection Vulnerabilities. 34th IEEE/ACM International Conference on Automated Software Engineering (ASE), 1286-1288. Kranthikumar B. and Leela V. (2020). SQL injection detection using REGEX classifier. Journal of Xi'an University of Architecture & Technology. 12(6), 800-809. Landi, F.; Baraldi, L.; Cornia, M.; Cucchiara, R. (2021). Working memory connections for LSTM. Neural Netw. 144, 334–341. Li, Q., Li, W., Wang, J. & Cheng, M. (2019). A SQL Injection Detection Method based on Adaptive Deep Forest. IEEE Access. 1-1. 10.1109/ACCESS.2019.2944951. Luo A., Wei H., Wenqing F. (2019). A CNN-based Approach to the Detection of SQL Injection Attacks. 18th International Conference on Computer and Information Science (ICIS), 320-324, doi: 10.1109/ICIS46139.2019.8940196. Maraj A., Rogova E., Jakupi G., and Grajcevci X. (2017). Testing techniques and analysis of SQL injection attacks, in Proc. Int. Conf. Knowl. Eng. Appl. (ICKEA), 1–11. Mavromoustakos S., Patel A., Chaudhary K., Chokshi P., and Patel S. (2016). Causes and prevention of SQL injection attacks in web applications. ACM Int. Conf. Proceeding Ser., 55–59. Musaab F. (2020). Intrusion detection: Approaches, datasets, and comparative study, J. Inf. Secure. Appl., 50. Muyang L., Ke L., Tao C. (2020). DeepSQLi: Deep Semantic Learning for Testing SQL Injection. Virtual Event, 288-297. Peng T. , Weidong Q., Zheng H., Huijuan L., Guozhen L. (2020). Detection of SQL injection based on artificial neural network. Knowledge-Based Systems. 190(2020), 1-10. Wang, Q., Li, C., Wang, D., Yuan, L., Pan, G., Cheng, Y., Hu, M., and Ren, Y. (2024). IGXSS: XSS payload detection model based on inductive GCN. International Journal of Network Management. 34. 10.1002/nem.2264.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY

Advances in Algorithmic Contract Scoring for Pre-Negotiation Yield Optimization and Risk Retention

Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones

DevTest flow: Designing a Scalable Continuous Testing Pipeline for High-Velocity Software Delivery

Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun