SSQLi: A Black-Box Adversarial Attack Method for SQL Injection Based on Reinforcement Learning

نویسندگان

چکیده

SQL injection is a highly detrimental web attack technique that can result in significant data leakage and compromise system integrity. To counteract the harm caused by such attacks, researchers have devoted much attention to examination of detection techniques, which progressed from traditional signature-based methods machine- deep-learning-based models. These techniques demonstrated promising results on existing datasets; however, most studies overlooked impact adversarial particularly black-box methods. This study addressed shortcomings current proposed reinforcement-learning-based method. The proposal included an innovative vector transformation approach for original payload, comprehensive attack-rule matrix, method adaptive generation examples. Our was evaluated application firewalls (WAF) models based deep-learning methods, generated examples successfully bypassed at rate up 97.39%. Furthermore, there substantial decrease accuracy model after multiple attacks had been carried out via

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Tactics of Adversarial Attack on Deep Reinforcement Learning Agents

We introduce two tactics, namely the strategicallytimed attack and the enchanting attack, to attack reinforcement learning agents trained by deep reinforcement learning algorithms using adversarial examples. In the strategically-timed attack, the adversary aims at minimizing the agent’s reward by only attacking the agent at a small subset of time steps in an episode. Limiting the attack activit...

متن کامل

Testing for Tautology based SQL Injection Attack using Runtime Monitors

Today, all commercial and business applications (ecommerce, banking, blogs, web mail, etc.,) are built as webbased database applications. Increasing prominence and usage of these applications has made them more susceptible to attacks because they store huge amount of sensitive user information. Traditional security mechanisms like network firewalls, intrusion detection systems, and use of encry...

متن کامل

An Approach for Preventing SQL Injection Attack on Web Application

SQL injection attacks are one of the highest dangers for applications composed for the Web. These attacks are dispatched through uncommonly made client information on web applications that utilization low level string operations to build SQL queries.SQL injection weakness permits an assailant to stream summons straightforwardly to a web application's hidden database and annihilate usefulness or...

متن کامل

A Study on Disclosure and Avoidance of SQL Injection Attack

Many software systems include a web-based element that makes them available to the public via the internet and can expose them to a variety of web-based attacks. One of these attacks is SQL injection which can give attackers illegal access to the databases. This paper presents a way to prevent web applications against SQL injection. Pattern matching is a system that can be used to distinguish o...

متن کامل

Blocking Transferability of Adversarial Examples in Black-Box Learning Systems

Advances in Machine Learning (ML) have led to its adoption as an integral component in many applications, including banking, medical diagnosis, and driverless cars. To further broaden the use of ML models, cloud-based services offered by Microsoft, Amazon, Google, and others have developed ML-as-a-service tools as black-box systems. However, ML classifiers are vulnerable to adversarial examples...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Future Internet

سال: 2023

ISSN: ['1999-5903']

DOI: https://doi.org/10.3390/fi15040133