机器学习在SQL注入攻击检测中的应用
2021-07-22刘绍廷杨孟英朱广全袁媛
刘绍廷 杨孟英 朱广全 袁媛



摘 要:本文以结构化查询语言(SQL)为研究对象,利用词袋(BoW)模型和词频-逆文档频率(TF-IDF)算法两种方法进行SQL语句向量化。文本向量化后,特征矩阵维数大大增加,很难在后面数据训练和预测中使用。为解决这个问题,对大量SQL注入攻击语句与用户正常输入的SQL语句进行研究分析,概括出28个特征关键词。同时,使用决策树、XGBoost和随机森林三个分类模型,对数据集进行模型训练及预测。实验结果表明:与词袋(BoW)模型相比,词频-逆文档频率(TF-IDF)算法的准确率、召回率、F分数、精确率均提高了10%左右。此外,ROC曲线也说明了该方法的有效性。
关键词:TF-IDF;SQL注入攻击;文本向量化;机器学习
中图分类号:TP393.08文献标识码:A文章编号:1003-5168(2021)08-0023-05
Application of Machine Learning in SQL Injection Attack Detection
LIU Shaoting YANG Mengying ZHU Guangquan YUAN Yuan
(Hebei Institute of Mechanical and Electrical Technology,Xingtai Hebei 054000)
Abstract: This paper took structured query language (SQL) as the research object, and used BoW model and TF-IDF algorithm to vectorize SQL statements. After the text is quantized, the dimension of feature matrix is greatly increased, which is difficult to use in the data training and prediction. To solve this problem, a large number of SQL injection attack statements and normal SQL statements were analyzed, and 28 key words were summarized. At the same time, the data set was trained and predicted by using three classification models: decision tree, XGBoost and random forest. The experimental results show that the accuracy, recall rate, f score and accuracy rate of TF-IDF algorithm are improved by about 10% compared with the BoW model. In addition, ROC curve also shows the effectiveness of the method.
Keywords: TF-IDF;SQL injection attacks;text vectorization;machine leaning
随着计算机互联网技术的广泛应用,各种互联网服务水平不断提升。但由于设计人员和程序员的疏忽、水平和经验参差不齐等,部分应用程序存在大量的安全漏洞。依据2017年打开Web应用程序安全项目(Open Web Application Security Project,OWASP)互联网应用安全风险评估的结果,注入类攻击在排名前十的互联网攻击行为中名列第一位。其中,结构化查询语言(Structured Query Language,SQL)注入攻击作为一种常见的应用层注入攻击,备受学术界和工业界的关注[1]。SQL注入是网络上经常使用的攻击手段,具有变种极多、攻击简单、危害极大的特点。利用机器学习检测SQL注入攻击已成为一种趋势。
1 基本知识原理及分類
1.1 SQL注入攻击原理及分类
SQL注入攻击是黑客对数据库进行攻击的常用手段之一。SQL注入的根本原因是代码没有对用户输入数据的合法性进行验证,直接拼接到查询语句中。……
