Electronic Thesis/Dissertation
 

An artificial intelligence model for the exploitation of SQL injection vulnerabilities in web applications

Open Access Deposited

The purpose of the research is to evaluate the existing Structured Query Language(SQL) injection (SQLi) exploitation tools and models based on an evaluation framework consisting of five dimensions of novelty, diversity, validity, semantic correctness, and Web Application Firewall (WAF) evasive capabilities. Then, sequence-based and feedback- directed AI models were used to generate payloads for in-depth analysis of their real-world applications and limitations. The purpose of this research is to discover unseen SQLi vulnerabilities in web applications by generating and applying new attack payloads. Therefore, research adopted an exploratory, experimental, and analytical approach. First, the limitations of existing SQLi exploitation solutions were identified through the exploration of the literature review and by applying tools against the simulated test environment. Then, Text Generative Adversarial Network (TextGAN) and stacked Long Short Term Memory (LSTM) standalone models were trained on the SQLi payloads dataset to generate novel, diverse, valid, and semantically correct payloads. The payloads generated were analyzed based on the proposed evaluation framework to test their effectiveness and real-world applicability. The results of the research showed that existing SQLi exploitation tools and models lack a balance between novelty, diversity, validity, semantic correctness, and WAF bypass. Stand-alone models without feedback can enhance the novelty and diversity of the generated payloads, but the syntax and effectiveness of the generated payloads were compromised. While feedback-based Artificial Intelligence (AI) models can provide a balance between these dimensions by enforcing novelty, diversity, validity, semantic correctness, and evasive capabilities in generated payloads. This directed approach can yield unseen attack payloads to discover vulnerabilities in web applications and firewalls.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Ahmed_gwu_0075A_17502.pdf Ahmed_gwu_0075A_17502.pdf 2025-12-11 Open Access