SQL injection attack detection method using expectation criterion

Linghuan Xiao, Shinichi Matsumoto, Tomohisa Ishikawa, Kouichi Sakurai

Research output: Chapter in Book/Report/Conference proceedingConference contribution

3 Citations (Scopus)

Abstract

SQL Injection attack is a kind of attack to a web application that accesses the database of the web application illegitimate. Along with the increasing use of web applications, the database where stores much sensitive information became more and more valuable and vulnerable. Eventually, SQL Injection attack has become rank one in top ten vulnerabilities as specified by Open Web Application Security Project (OWASP). In the other hand, although there was proposed a lot of methods to address the SQL injection attack, the current approaches almost have the limitation to detect full scope of the attack. What is more, the approaches have high precision in detecting pre-existing attacks though, but cannot detect unknown attacks. In this paper, we present an expectation-based solution to address SQL injection attack. Our proposal mainly has two phases. In the first phase, we calculate the occurrence probability of the SQL injection attack special characters in attack dataset and typical dataset respectively, and in the second phase we detect SQL injection attack base on expectation calculating take advantage of the computed occurrence probability.

Original languageEnglish
Title of host publicationProceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages649-654
Number of pages6
ISBN (Electronic)9781509026555
DOIs
Publication statusPublished - Jan 13 2017
Event4th International Symposium on Computing and Networking, CANDAR 2016 - Hiroshima, Japan
Duration: Nov 22 2016Nov 25 2016

Publication series

NameProceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016

Other

Other4th International Symposium on Computing and Networking, CANDAR 2016
CountryJapan
CityHiroshima
Period11/22/1611/25/16

All Science Journal Classification (ASJC) codes

  • Computer Science Applications
  • Hardware and Architecture
  • Signal Processing
  • Computer Networks and Communications

Cite this

Xiao, L., Matsumoto, S., Ishikawa, T., & Sakurai, K. (2017). SQL injection attack detection method using expectation criterion. In Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016 (pp. 649-654). [7818686] (Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016). Institute of Electrical and Electronics Engineers Inc.. https://doi.org/10.1109/CANDAR.2016.74

SQL injection attack detection method using expectation criterion. / Xiao, Linghuan; Matsumoto, Shinichi; Ishikawa, Tomohisa; Sakurai, Kouichi.

Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016. Institute of Electrical and Electronics Engineers Inc., 2017. p. 649-654 7818686 (Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016).

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Xiao, L, Matsumoto, S, Ishikawa, T & Sakurai, K 2017, SQL injection attack detection method using expectation criterion. in Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016., 7818686, Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016, Institute of Electrical and Electronics Engineers Inc., pp. 649-654, 4th International Symposium on Computing and Networking, CANDAR 2016, Hiroshima, Japan, 11/22/16. https://doi.org/10.1109/CANDAR.2016.74
Xiao L, Matsumoto S, Ishikawa T, Sakurai K. SQL injection attack detection method using expectation criterion. In Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016. Institute of Electrical and Electronics Engineers Inc. 2017. p. 649-654. 7818686. (Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016). https://doi.org/10.1109/CANDAR.2016.74
Xiao, Linghuan ; Matsumoto, Shinichi ; Ishikawa, Tomohisa ; Sakurai, Kouichi. / SQL injection attack detection method using expectation criterion. Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016. Institute of Electrical and Electronics Engineers Inc., 2017. pp. 649-654 (Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016).
@inproceedings{3975ccc90312432dbc88206187d85fcf,
title = "SQL injection attack detection method using expectation criterion",
abstract = "SQL Injection attack is a kind of attack to a web application that accesses the database of the web application illegitimate. Along with the increasing use of web applications, the database where stores much sensitive information became more and more valuable and vulnerable. Eventually, SQL Injection attack has become rank one in top ten vulnerabilities as specified by Open Web Application Security Project (OWASP). In the other hand, although there was proposed a lot of methods to address the SQL injection attack, the current approaches almost have the limitation to detect full scope of the attack. What is more, the approaches have high precision in detecting pre-existing attacks though, but cannot detect unknown attacks. In this paper, we present an expectation-based solution to address SQL injection attack. Our proposal mainly has two phases. In the first phase, we calculate the occurrence probability of the SQL injection attack special characters in attack dataset and typical dataset respectively, and in the second phase we detect SQL injection attack base on expectation calculating take advantage of the computed occurrence probability.",
author = "Linghuan Xiao and Shinichi Matsumoto and Tomohisa Ishikawa and Kouichi Sakurai",
year = "2017",
month = "1",
day = "13",
doi = "10.1109/CANDAR.2016.74",
language = "English",
series = "Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
pages = "649--654",
booktitle = "Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016",
address = "United States",

}

TY - GEN

T1 - SQL injection attack detection method using expectation criterion

AU - Xiao, Linghuan

AU - Matsumoto, Shinichi

AU - Ishikawa, Tomohisa

AU - Sakurai, Kouichi

PY - 2017/1/13

Y1 - 2017/1/13

N2 - SQL Injection attack is a kind of attack to a web application that accesses the database of the web application illegitimate. Along with the increasing use of web applications, the database where stores much sensitive information became more and more valuable and vulnerable. Eventually, SQL Injection attack has become rank one in top ten vulnerabilities as specified by Open Web Application Security Project (OWASP). In the other hand, although there was proposed a lot of methods to address the SQL injection attack, the current approaches almost have the limitation to detect full scope of the attack. What is more, the approaches have high precision in detecting pre-existing attacks though, but cannot detect unknown attacks. In this paper, we present an expectation-based solution to address SQL injection attack. Our proposal mainly has two phases. In the first phase, we calculate the occurrence probability of the SQL injection attack special characters in attack dataset and typical dataset respectively, and in the second phase we detect SQL injection attack base on expectation calculating take advantage of the computed occurrence probability.

AB - SQL Injection attack is a kind of attack to a web application that accesses the database of the web application illegitimate. Along with the increasing use of web applications, the database where stores much sensitive information became more and more valuable and vulnerable. Eventually, SQL Injection attack has become rank one in top ten vulnerabilities as specified by Open Web Application Security Project (OWASP). In the other hand, although there was proposed a lot of methods to address the SQL injection attack, the current approaches almost have the limitation to detect full scope of the attack. What is more, the approaches have high precision in detecting pre-existing attacks though, but cannot detect unknown attacks. In this paper, we present an expectation-based solution to address SQL injection attack. Our proposal mainly has two phases. In the first phase, we calculate the occurrence probability of the SQL injection attack special characters in attack dataset and typical dataset respectively, and in the second phase we detect SQL injection attack base on expectation calculating take advantage of the computed occurrence probability.

UR - http://www.scopus.com/inward/record.url?scp=85015222622&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=85015222622&partnerID=8YFLogxK

U2 - 10.1109/CANDAR.2016.74

DO - 10.1109/CANDAR.2016.74

M3 - Conference contribution

AN - SCOPUS:85015222622

T3 - Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016

SP - 649

EP - 654

BT - Proceedings - 2016 4th International Symposium on Computing and Networking, CANDAR 2016

PB - Institute of Electrical and Electronics Engineers Inc.

ER -