首页> 中文期刊>计算机与现代化 >一种基于神经网络的SQL注入漏洞的检测模型

一种基于神经网络的SQL注入漏洞的检测模型

     

摘要

A novel approach to detect injection attacks was presented by identifying characteristics of injection attacks and using a neural network model to determine the likelihood that a given query is malicious. Based on the recognition of SQL character injec-tion attack, the analysis model comes into being used to determine whether to inject SQL statements of model by using a large number of known data and the neural network algorithm. After that, based on the neural network model presented, the user input SQL statement can be directly analyzed and processed. This approach is implemented in a proxy that locates between a Web ap-plication and a database and prevents suspected malicious queries from being executed. This requires no modification of existing application code and is capable of identifying un-known attacks. Experimental results show that the model can effectively improve the accuracy and efficiency of the detection.%针对SQL注入漏洞检测问题,本文提出一种基于人工神经元网络的SQL注入漏洞的分析模型。该模型在识别SQL关键字注入攻击特点的基础上,利用人工神经元网络算法对SQL注入语句进行检测,能够直接分析SQL语句,判断用户输入的SQL语句是否为SQL注入的语句。实现上,通过在Web应用程序和数据库中间加一个代理来实现分析和检测过程,从而无需修改已有应用的代码。通过对实验结果的分析证明该模型可提高SQL注入漏洞检测的准确率和执行效率。

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号