SQLi Detection with ML: A Data-Source Perspective

Published: 2023, Last Modified: 25 Sept 2025SECRYPT 2023EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Almost 50 years after the invention of SQL, injection attacks are still top-tier vulnerabilities of today’s ICT systems. In this work, we highlight the shortcomings of the previous Machine Learning based results and fill the identified gaps by providing a comprehensive empirical analysis. We cross-validate the trained models by using data from other distributions which was never studied in relation with SQLi. Finally, we validate our findings on a real-world industrial SQLi dataset.
Loading