International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1712995

1712995 Vol 9 · Issue 6 Download Paper

A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi

Pushkar Y Jane , Roshani K Mukadam

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Security

DOI: 10.64388/IREV9I6-1712995

Abstract

SQL Injection (SQLi) remains one of the most persistent and damaging classes of web application vulnerabilities. As attackers adopt more sophisticated techniques ? obfuscation, blind channels, and time-based inference ? traditional detection techniques (rule/signature based and shallow ML) show limited robustness. Recently, hybrid approaches that combine feature selection, classical machine learning (ML) for fast filtering, and deep learning (DL) for semantic verification have gained traction. This survey thoroughly analyzes contemporary SQL Injection (SQLi) detection methods, specifically focusing on hybrid architectures capable of identifying obfuscated, blind, and time-based variants. This section details the SQLi attack taxonomy and corresponding defensive mechanisms. It further explores the application of advanced feature engineering techniques, such as Chi-Square ranking, to enhance detection. The analysis concludes with a performance evaluation (benchmarking) of both Machine Learning (ML) and Deep Learning (DL) models employed in this security domain.

References

[1] C. Anley, “Advanced SQL Injection in SQL Server Applications,” NGSSoftware Insight Security Research, 2002.

[2] I. Guyon and A. Elisseeff, “An introduction to variable and feature selection,” Journal of Machine Learning Research, vol. 3, pp. 1157–1182, 2003.

[3] W. G. Halfond, J. Viegas, and A. Orso, “A classification of SQL-injection attacks and countermeasures,” in Proc. IEEE Int. Symp. Secure Software Engineering, 2006, pp. 13–15.

[4] W. G. Halfond and A. Orso, “Preventing SQL injection attacks using AMNESIA,” in Proc. 28th Int. Conf. Software Engineering (ICSE), 2006, pp. 795–798.

[5] S. Bandhakavi, P. Bisht, P. Madhusudan, and V. N. Venkatakrishnan, “CANDID: Preventing SQL injection attacks using dynamic candidate evaluations,” in Proc. 14th ACM Conf. Computer and Communications Security (CCS), 2007, pp. 12–24.

[6] R. Valeur, D. Mutz, and G. Vigna, “A learning-based approach to the detection of SQL attacks,” in Proc. Int. Conf. Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2005, pp. 123–140.

[7] J. Newsome, B. Karp, and D. Song, “Polygraph: Automatically generating signatures for polymorphic worms,” in Proc. IEEE Symp. Security and Privacy, 2005, pp. 226–241.

[8] A. Tajpour, M. J. Z. Ghahramani, and H. Ibrahim, “SQL injection detection using machine learning,” in Proc. Int. Conf. Education and Management Technology, 2010, pp. 40–43.

[9] R. Karimi, M. Fathy, and M. P. Fard, “Detection of SQL injection attacks using machine learning based techniques,” Int. J. Computer Science and Information Security, vol. 8, no. 6, pp. 1–6, 2010.

[10] J. Kim, J. Kim, and S. Kim, “SQL injection attack detection using character distribution and entropy analysis,” IEEE Access, vol. 7, pp. 162202–162214, 2019.

[11] Y. Zhang, Q. Zhang, and J. Yang, “Detecting SQL injection attacks using deep learning,” Future Generation Computer Systems, vol. 102, pp. 557–566, 2020.

[12] Z. Chen, J. Meng, and Y. Li, “Detecting SQL injection attacks based on convolutional neural networks,” Applied Sciences, vol. 10, no. 3, pp. 1–17, 2020.

[13] M. Roichman and R. Gudes, “Fine-grained access control to web databases,” in Proc. ACM Conf. Computer and Communications Security (CCS), 2007, pp. 31–40.

[14] T. Mikolov et al., “Efficient estimation of word representations in vector space,” in Proc. Int. Conf. Learning Representations (ICLR), 2013.

How to cite this paper

Pushkar Y Jane , , Roshani K Mukadam "A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi" Iconic Research And Engineering Journals Volume 9 Issue 6 2025 Page 1485-1489 https://doi.org/10.64388/IREV9I6-1712995
Pushkar Y Jane , , Roshani K Mukadam "A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi" Iconic Research And Engineering Journals, vol. 9, no. 6, Dec. 2025, doi: https://doi.org/10.64388/IREV9I6-1712995
Pushkar Y Jane , , Roshani K Mukadam (2025). A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi. Iconic Research And Engineering Journals, 9(6). doi: https://doi.org/10.64388/IREV9I6-1712995
Pushkar Y Jane , , Roshani K Mukadam "A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi" Iconic Research And Engineering Journals, vol. 9, no. 6, Dec. 2025. Crossref, https://doi.org/10.64388/IREV9I6-1712995
@article{1712995,
      author = {Pushkar Y Jane , , Roshani K Mukadam},
      title = {A Survey on Hybrid SQL Injection Detection: Feature-Selection, Classical Machine Learning, and Deep Learning Approaches to Obfuscated, Blind, and Time-Based SQLi},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {9},
      number = {6},
      pages = {1485-1489},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1712995.pdf},
      abstract = {SQL Injection (SQLi) remains one of the most persistent and damaging classes of web application vulnerabilities. As attackers adopt more sophisticated techniques ? obfuscation, blind channels, and time-based inference ? traditional detection techniques (rule/signature based and shallow ML) show limited robustness. Recently, hybrid approaches that combine feature selection, classical machine learning (ML) for fast filtering, and deep learning (DL) for semantic verification have gained traction. This survey thoroughly analyzes contemporary SQL Injection (SQLi) detection methods, specifically focusing on hybrid architectures capable of identifying obfuscated, blind, and time-based variants. This section details the SQLi attack taxonomy and corresponding defensive mechanisms. It further explores the application of advanced feature engineering techniques, such as Chi-Square ranking, to enhance detection. The analysis concludes with a performance evaluation (benchmarking) of both Machine Learning (ML) and Deep Learning (DL) models employed in this security domain.},
      month = {December},
      doi = {https://doi.org/10.64388/IREV9I6-1712995}
  }