Skip to content
Open access

Enhancing SQL Injection Detection: A Machine Learning Approach Using Network Flow Data

Aug 2026 · Journal of Computer Science · 0 citations · 40 references

TL;DR

A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.

Abstract

: Background: SQL injection is one of the cyberattacks which occurs in web application vulnerabilities. It targets the poor input validation and enables the attackers to inject malicious queries into the database fields in any application. It will grant access to unauthorized users and data modification, or they will take control over the complete database. To prevent this, there are several traditional methods, like Intrusion Detection Systems (IDS) and packet inspection methods, which will detect these attacks by each and every network packet in the network traffic. Methods: The existing methods also have some limitations due to computational overhead due to monitoring each and every packet. It makes it challenging for high-end routers and large-scale networks as it monitors all the individual traffic. To resolve this problem, propose a flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks. Unlike traditional methods, which require more inspection on individual packets, flow-based analysis uses mandatory communication metadata, like source and destination IP addresses, port numbers, etc. It minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions. Results: In order to validate this approach, we gathered two collections of data, which included net flow data of SQLI attacks of database systems such as SQL, postgres SQL, etc. It has both normal and bad traffic, and we applied machine learning models to the traffic. Conclusion: The results indicate that the proposed flow-based method is more efficient and scalable for detecting SQL injection attacks than packet-based inspection.

Read PDF

Similar papers

Open access Sep 2026

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space.

Zeyneb Berkat, Amina Fatima Zahra Yahiaoui, Mahfoud Aliouat et al. · 0 citations
Open access Sep 2026

Intrusion detection in secure shell using Multilayer Perceptron

A predictive model which uses an idea of detecting intrusion in a network is capable of recognizing intrusions or attacks as "1" and normal connections as “0” using Multilayer Perceptron (MLP) classification.

Amit Chapagain · 0 citations
Conference Sep 2026

Network Intrusion Detection Using SNMP MIB Data: A Multi-Device Machine Learning Approach

The increasing complexity and volume of network traffic have made the accurate and timely detection of cyber-attacks a critical challenge. This study proposes a machine learning-based intrusion detection approach using Simple Network Management Protocol - Management Information Base (SNMP-MIB) data collected from four...

Emirhan Erdem, M. Karakose, Kürşat İnce · 0 citations
#software testing Conference Open access Sep 2026

REAL-TIME NETWORK TRAFFIC CAPTURE AND ANALYSIS USING A DEEP NEURAL NETWORK

Several deep neural networks are compared, namely One-dimensional convolution neural network/1D CNN, Long Short-Term Memory/LSTM and Autoencoder, to reveal the ability of deep neural networks to correctly model the behavior of network traffic and ultimately increase the recognition of compromised data.

Angela Borisova, Krasimir Slavyanov · 0 citations
Open access Aug 2026

A Machine Learning-Based Approach for Detecting DNS Tunneling and Data Exfiltration in Network Traffic

The Domain Name System (DNS) is a foundational protocol of the Internet, and its near-universal permission through firewalls makes it an attractive covert channel for attackers seeking to tunnel data or exfiltrate sensitive information. DNS tunneling techniques encode arbitrary data inside DNS queries and responses, al...

Ajay, Deepika Kumawat, Atharva Sharma et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.