Skip to main navigation Skip to search Skip to main content

Human agent knowledge transfer applied to web security

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Web Applications today rely heavily on database for storage of information & processing of the same. In the same time plenty of threats & security attacks are being launched against web - applications that are aimed to inject commands and gain unauthorized access to the sensitive information from the back-end database. Plenty of attacks exploit vulnerabilities of web-based applications, with majority because of input validation flaws. If the input provided by user is not sanitized correctly, then it is easily possible to launch variety of attacks that force web-based applications to compromise the security of back-end databases. In this work we propose a novel approach for detecting the SQL Injection attacks by applying TD machine learning technique. In this approach first the SQL query is compared with KB and if the query matches KB then it is a genuine query and database access is given. But in case of SQLIA queries, they are subjected to tokenization and then SQL query analysis is performed. A model based RL using TD learning is developed to distinguish between genuine & SQLIA queries. In the model, if the query traverses the path & reaches final state with higher rewards then it is termed as a SQLIA query.

Original languageEnglish
Title of host publication2013 4th International Conference on Computing, Communications and Networking Technologies, ICCCNT 2013
DOIs
Publication statusPublished - 2013
Event2013 4th International Conference on Computing, Communications and Networking Technologies, ICCCNT 2013 - Tiruchengode, India
Duration: 04-07-201306-07-2013

Publication series

Name2013 4th International Conference on Computing, Communications and Networking Technologies, ICCCNT 2013

Conference

Conference2013 4th International Conference on Computing, Communications and Networking Technologies, ICCCNT 2013
Country/TerritoryIndia
CityTiruchengode
Period04-07-1306-07-13

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Human agent knowledge transfer applied to web security'. Together they form a unique fingerprint.

Cite this