Detection of SQL Injection Using a Genetic Fuzzy Classifier System

Abstract

SQL Injection (SQLI) is one of the most popular vulnerabilities of web applications. The consequences of SQL injection attack include the possibility of stealing sensitive information or bypassing authentication procedures. SQL injection attacks have different forms and variations. One difficulty in detecting malicious attacks is that such attacks do not have a specific pattern. A new fuzzy rule-based classification system (FBRCS) can tackle the requirements of the current stage of security measures. This paper proposes a genetic fuzzy system for detection of SQLI where not only the accuracy is a priority, but also the learning and the flexibility of the obtained rules. To create the rules having high generalization capabilities, our algorithm builds on initial rules, data-dependent parameters, and an enhancing function that modifies the rule evaluation measures. The enhancing function helps to assess the candidate rules more effectively based on decision subspace. The proposed system has been evaluated using a number of well-known data sets. Results show a significant enhancement in the detection procedure

Authors and Affiliations

Christine Basta, Ahmed elfatatry, Saad Darwish

Keywords

Related Articles

A Hindi Speech Actuated Computer Interface for Web Search

Aiming at increasing system simplicity and flexibility, an audio evoked based system was developed by integrating simplified headphone and user-friendly software design. This paper describes a Hindi Speech Actuated Compu...

Handwritten Digit Recognition based on Output-Independent Multi-Layer Perceptrons

With handwritten digit recognition being an established and significant problem that is facing computer vision and pattern recognition, there has been a great deal of research work that has been undertaken in this area....

A Comparative Study of Meta-heuristic Algorithms for Solving Quadratic Assignment Problem

Quadratic Assignment Problem (QAP) is an NP-hard combinatorial optimization problem, therefore, solving the QAP requires applying one or more of the meta-heuristic algorithms. This paper presents a comparative study betw...

Improved Tracking Using a Hybrid Optcial-Haptic Three-Dimensional Tracking System

The aim of this paper is to asses to what extent an optical tracking system (OTS) used for position tracking in virtual reality can be improved by combining it with a human scale haptic device named Scalable-SPIDAR. The...

 Multi-Objective Intelligent Manufacturing System for Multi Machine Scheduling

This paper proposes a framework for Intelligent Manufacturing systems in which the machine scheduling is achieved by MCDM and DRSA. The relationship between perception/knowledge base and profit maximization is being exte...

Download PDF file
  • EP ID EP112470
  • DOI 10.14569/IJACSA.2016.070616
  • Views 101
  • Downloads 0

How To Cite

Christine Basta, Ahmed elfatatry, Saad Darwish (2016). Detection of SQL Injection Using a Genetic Fuzzy Classifier System. International Journal of Advanced Computer Science & Applications, 7(6), 129-137. https://europub.co.uk./articles/-A-112470