An artificial intelligence model for the exploitation of SQL injection vulnerabilities in web applications
Open Access DepositedThe purpose of the research is to evaluate the existing Structured Query Language(SQL) injection (SQLi) exploitation tools and models based on an evaluation framework consisting of five dimensions of novelty, diversity, validity, semantic correctness, and Web Application Firewall (WAF) evasive capabilities. Then, sequence-based and feedback- directed AI models were used to generate payloads for in-depth analysis of their real-world applications and limitations. The purpose of this research is to discover unseen SQLi vulnerabilities in web applications by generating and applying new attack payloads. Therefore, research adopted an exploratory, experimental, and analytical approach. First, the limitations of existing SQLi exploitation solutions were identified through the exploration of the literature review and by applying tools against the simulated test environment. Then, Text Generative Adversarial Network (TextGAN) and stacked Long Short Term Memory (LSTM) standalone models were trained on the SQLi payloads dataset to generate novel, diverse, valid, and semantically correct payloads. The payloads generated were analyzed based on the proposed evaluation framework to test their effectiveness and real-world applicability. The results of the research showed that existing SQLi exploitation tools and models lack a balance between novelty, diversity, validity, semantic correctness, and WAF bypass. Stand-alone models without feedback can enhance the novelty and diversity of the generated payloads, but the syntax and effectiveness of the generated payloads were compromised. While feedback-based Artificial Intelligence (AI) models can provide a balance between these dimensions by enforcing novelty, diversity, validity, semantic correctness, and evasive capabilities in generated payloads. This directed approach can yield unseen attack payloads to discover vulnerabilities in web applications and firewalls.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.