节点文献

基于深度学习的SQL注入检测算法的研究与应用

Research and Application of SQL Injection Detection Algorithm Based on Deep Learning

【作者】 张晓霞;

【导师】 王齐;

【作者基本信息】 山西大学 , 计算机技术, 2025, 硕士

【摘要】 随着网络应用的快速发展,SQL注入攻击已成为网络安全领域的重大威胁。攻击者通过利用应用程序对用户输入验证机制的缺陷,构造恶意SQL指令实施数据库渗透,可导致核心数据窃取、存储结构破坏等严重后果。因此,精准、高效地检测SQL注入攻击对保障网络安全来说意义重大。针对当前深度学习技术在SQL注入检测中面临的数据集多样性不足、特征提取不全面以及新型攻击识别困难等问题,本文展开深入研究并提出一系列解决方案,以提升SQL注入检测能力。具体工作如下:(1)针对现有公开数据集在攻击类型和样本数量上的不足,通过多数据源收集SQL注入攻击样本,构建了更具多样性的数据集。数据来源包括公开的HTTP CSIC2010数据集、Git Hub中已发布的样本以及利用SQLMAP和Burp Suite采集的样本。(2)针对传统特征提取方法在SQL注入检测中的局限性,提出了SSA-Feature特征提取方法。该方法结合TF-IDF、Word2Vec和Autoencoder三种技术,从统计、语义和降维的角度对SQL注入攻击样本进行特征提取。经实验验证,SSA-Feature能够从多个维度挖掘SQL注入攻击样本的深层语义特征,有效弥补传统方法在特征覆盖广度和深度上的不足。(3)针对深度学习模型在SQL注入检测中难以识别新型攻击的问题,提出基于SSA-Feature特征提取的iPGRU检测模型。该模型融合iPNN和Bi-GRU的优势,iPNN利用增量学习机制动态适应新型攻击模式,Bi-GRU对SQL请求文本进行时序建模,捕捉深层次语义信息。实验表明,iPGRU模型在准确率、精确率、召回率和误报率等指标上表现突出,在识别新型攻击方面具有显著优势。(4)设计并实现基于深度学习的SQL注入检测系统。本系统在设计中充分应用了本文的研究成果构建了SQL注入检测系统。系统包括数据采集、数据处理、模型检测、风险评估和结果展示五个模块。数据采集模块支持多源数据实时获取;数据处理模块利用SSA-Feature自动提取关键特征,为iPGRU模型提供高质量输入;模型检测模块借助iPGRU高效识别SQL注入攻击;风险评估模块依据检测结果进行分级;结果展示模块使用直观图表来展示检测效果。

【Abstract】 With the rapid development of network applications,SQL injection attacks have become a major threat in the field of network security.Attackers exploit the defects of the application’s user input validation mechanism to construct malicious SQL instructions to implement database penetration,which can lead to serious consequences such as core data theft and storage structure destruction.Therefore,accurate and efficient detection of SQL injection attacks is of great significance to network security.In view of the problems faced by current deep learning technology in SQL injection detection,such as insufficient dataset diversity,incomplete feature extraction,and difficulty in identifying new attacks,this paper conducts in-depth research and proposes a series of solutions to improve SQL injection detection capabilities.The specific work is as follows:(1)In view of the shortcomings of existing public datasets in terms of attack types and sample quantity,SQL injection attack samples are collected from multiple data sources to construct a more diverse dataset.The data sources include the public HTTP CSIC 2010 dataset,samples published in Git Hub,and samples collected using SQLMAP and Burp Suite.(2)In view of the limitations of traditional feature extraction methods in SQL injection detection,the SSA-Feature feature extraction method is proposed.This method combines TF-IDF,Word2Vec and Autoencoder to extract features from SQL injection attack samples from the perspectives of statistics,semantics and dimensionality reduction.Experimental verification shows that SSA-Feature can mine deep semantic features of SQL injection attack samples from multiple dimensions,effectively making up for the shortcomings of traditional methods in feature coverage breadth and depth.(3)Aiming at the problem that deep learning models are difficult to identify new attacks in SQL injection detection,an iPGRU detection model based on SSA-Feature feature extraction is proposed.This model combines the advantages of iPNN and Bi-GRU.iPNN uses incremental learning mechanism to dynamically adapt to new attack patterns,and Bi-GRU performs temporal modeling on SQL request text to capture deep semantic information.Experiments show that the iPGRU model performs well in terms of accuracy,precision,recall and false alarm rate,and has significant advantages in identifying new attacks.(4)Design and implement a SQL injection detection system based on deep learning.This system fully applies the research results of this paper in its design,and builds a SQL injection detection system based on the SSA-Feature feature extraction method and the iPGRU model.The system includes five modules:data acquisition,data processing,model detection,risk assessment,and result display.The data acquisition module supports real-time acquisition of multi-source data;the data processing module uses SSA-Feature to automatically extract key features and provide high-quality input for the iPGRU model;the model detection module uses iPGRU to efficiently identify SQL injection attacks;the risk assessment module is graded according to the detection results;and the result display module uses intuitive charts to display the detection effect.

  • 【网络出版投稿人】 山西大学
  • 【网络出版年期】2026年 05期
  • 【分类号】TP393.08;TP18
节点文献中: