• DocumentCode
    2542981
  • Title

    AIIDA-SQL: An Adaptive Intelligent Intrusion Detector Agent for detecting SQL Injection attacks

  • Author

    Pinzón, Cristian ; De Paz, Juan F. ; Bajo, Javier ; Herrero, Álvaro ; Corchado, Emilio

  • Author_Institution
    Fac. of Comput. Syst. Eng., Technol. Univ. of Panama, Panama City, Panama
  • fYear
    2010
  • fDate
    23-25 Aug. 2010
  • Firstpage
    73
  • Lastpage
    78
  • Abstract
    SQL Injection attacks on web applications have become one of the most important information security concerns over the past few years. This paper presents a hybrid approach based on the Adaptive Intelligent Intrusion Detector Agent (AIIDA-SQL) for the detection of those attacks. The AIIDA-SQL agent incorporates a Case-Based Reasoning (CBR) engine which is equipped with learning and adaptation capabilities for the classification of SQL queries and detection of malicious user requests. To carry out the tasks of attack classification and detection, the agent incorporates advanced algorithms in the reasoning cycle stages. Concretely, an innovative classification model based on a mixture of an Artificial Neuronal Network together with a Support Vector Machine is applied in the reuse stage of the CBR cycle. This strategy enables to classify the received SQL queries in a reliable way. Finally, a projection neural technique is incorporated, which notably eases the revision stage carried out by human experts in the case of suspicious queries. The experimental results obtained on a real-traffic case study show that AIIDA-SQL performs remarkably well in practice.
  • Keywords
    SQL; case-based reasoning; neural nets; security of data; support vector machines; AIIDA-SQL agent; CBR engine; SQL injection attack detecting; SQL queries classification; adaptive intelligent intrusion detector agent; artificial neuronal network; case-based reasoning engine; information security; malicious user requests detection; projection neural technique; support vector machine; web applications; Artificial neural networks; Book reviews; Classification algorithms; Cognition; Databases; Humans; Support vector machines; Agent; Artificial Neural Network; Case-Based Reasoning; Intrusion Detection; SQL Injection; Support Vector Machine;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Hybrid Intelligent Systems (HIS), 2010 10th International Conference on
  • Conference_Location
    Atlanta, GA
  • Print_ISBN
    978-1-4244-7363-2
  • Type

    conf

  • DOI
    10.1109/HIS.2010.5600026
  • Filename
    5600026