首页> 外国专利> Anomaly-based detection of SQL injection attacks

Anomaly-based detection of SQL injection attacks

机译:基于异常的SQL注入攻击检测

摘要

A method for detecting a SQL injection attack comprises a training phase and a detection phase. In the training phase, a plurality of SQL queries is transformed into a respective plurality of SQL token domain queries which are processed using a n-gram analysis to provide a threshold and an averaging vector. In the detection phase, each newly arrived SQL query is transformed into a new SQL token domain query, and the n-gram analysis is applied together with the averaging vector and the threshold to each new SQL token domain query to determine if the new SQL query is normal or abnormal. The detection may be online or offline.
机译:用于检测SQL注入攻击的方法包括训练阶段和检测阶段。在训练阶段,将多个SQL查询转换为相应的多个SQL令牌域查询,这些查询使用n元语法分析进行处理以提供阈值和平均向量。在检测阶段,将每个新到达的SQL查询转换为新的SQL令牌域查询,并将n-gram分析以及平均向量和阈值应用于每个新的SQL令牌域查询,以确定是否新的SQL查询是正常还是异常。检测可以是在线的或离线的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号