Detection and Mitigation of SQL Injection-based Attacks in Web Security

Authors

  • Nisha P. Shetty Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India https://orcid.org/0000-0002-4738-4713
  • Vinayak Kothari Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India https://orcid.org/0009-0004-6076-3680
  • Eva Hemantkumar Shah Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India https://orcid.org/0009-0000-4168-2245
  • Prashanth J. Kumar Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India https://orcid.org/0009-0001-3193-0126
  • Jayashree Shetty Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India https://orcid.org/0000-0003-0572-4553

DOI:

https://doi.org/10.13052/jmm1550-4646.2234

Keywords:

Cybersecurity, Machine Learning, SQL Injection, Web Security, intrusion detection, anomaly detection, deep learning, web security, network security, threat detection

Abstract

Crafty tactics like nested request bodies, encoding schemes, and JavaScript Object Notation (JSON) operators are now used by attackers to trick and bypass conventional Web application firewalls. The proposed machine learning-based system for detecting and mitigating SQL injection attacks is designed not just to protect against conventional SQLi attacks but also against JSON-based SQLi attacks, NoSQL injection attacks, hybrid attacks, and conventional WAF evasion techniques. The proposed system utilizes a stacking ensemble of Random Forest, Gradient Boosting, and Logistic Regression classifiers with manually constructed features that represent various properties of queries instead of using conventional static rule-based techniques or deep learning models. The detector is integrated into an application process that facilitates query inspection, batch analysis, decision explanation, and mitigation actions. The application is made available via a Flask-based REST API. To add structural variety, the dataset is constructed from public payload sources and augmented methodically. To support detections and to provide potential WAF rules, feature-level explanations are employed. The proposed work is also extended to incorporate a privacy-preserving federative learning framework to show its efficacy in collaborative environments. The system’s overall goal is to provide a modern, API-driven application as a complementary injection attack detection and monitoring layer suitable for quick, easy deployment.

Downloads

Download data is not yet available.

Author Biographies

Nisha P. Shetty, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India

Nisha P. Shetty received the B.E. and M.Tech. degrees in Computer Science and Engineering from Visvesvaraya Technological University (VTU), India, in 2013 and 2015, respectively, and the Ph.D. degree in Data Privacy and Security from Manipal Institute of Technology (MIT), Manipal Academy of Higher Education (MAHE), in 2023. She is currently an Associate Professor with the School of Computer Engineering (SCE), MIT, MAHE. She is a dedicated Academician. She is a Faculty Advisor for Project Cryptonite, one of the top-performing student projects at MIT, which has won accolades nationally and internationally. Her research interests include data privacy and security, with a focus on privacy-preserving frameworks in social networks, deep learning for medical diagnostics, and enhanced security measures for online data.

Vinayak Kothari, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India

Vinayak Kothari is a final-year B.Tech. student in Information Technology at Manipal Institute of Technology, Manipal, India. His research interests include cybersecurity, Web security, and software engineering. He is currently an intern at Tessell, where he contributes to technology-driven solutions in industry. He is passionate about applying research and innovation to address real-world computing and security challenges and intends to pursue a career in the technology industry.

Eva Hemantkumar Shah, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India

Eva Hemantkumar Shah is currently pursuing the B.Tech. degree in Information Technology (Honors) with a minor in cybersecurity at the Manipal Institute of Technology, Manipal, Karnataka, India, with an expected graduation in 2026. She is currently a Software Engineer at Microsoft, India. She previously completed internships at Microsoft, CNLABS, and Give. Her work includes various research projects applying machine learning and deep learning to security domains. Her current research interests include machine learning and cybersecurity. Shah is a member of the Institute of Engineering and Technology (IET). She received the IET Prize 2024 for showing outstanding performance in her engineering course.

Prashanth J. Kumar, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India

Prashanth J. Kumar is a Bachelor of Technology student in Information Technology at Manipal Institute of Technology, India. He has served as team leader of Cryptonite, one of India’s top Capture-the-Flag (CTF) teams and ethical hacking projects. His interests lie in Web-based attacks, cloud security, and embedded systems, and he is passionate about exploring and advancing cybersecurity.

Jayashree Shetty, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal-576104 Karnataka, India

Jayashree Shetty earned the B.E. degree in Computer Science and Engineering from CMRIT, Bangalore, India, and the M.Tech. degree in Computer Science and Engineering from SDIT, Mangalore. From 2014 to 2016, she worked as an Assistant Professor in the Department of Computer Science and Engineering, SDIT, Mangalore. In 2016, she joined the Manipal Institute of Technology as an Assistant Professor and is currently employed in the same institution. Her research interests include the field of medical image processing, artificial intelligence, and machine learning.

References

ExtraHop Networks, Inc., “SQL Injection (SQLi) Attacks: Definition, Examples, and Prevention,” ExtraHop. [Online]. Available: https://www.extrahop.com/resources/attacks/sqli. [Accessed: 09-Jan-2026].

OWASP, “OWASP Top 10:2025,” The Open Web Application Security Project, 2025. [Online]. Available: https://owasp.org/Top10/2025/. [Accessed: 09-Jan-2026].

J. Erickson, “What Is JSON?,” Oracle India, Apr. 4, 2024. [Online]. Available: https://www.oracle.com/in/database/what-is-json/. [Accessed: 09-Jan-2026].

S. L. Bjeladinovic, M. S. Asanovic, and N. M. Gospic, “An analysis of the JSON functionalities evolution across different versions of Oracle relational DBMS,” 2021. https://www.eventiotic.com/eventiotic/files/Papers/URL/ecfe7c82-5f54-416e-929d-d52ad9e993e4.pdf.

N. Moshe, “{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF,” Claroty Team82 Research, Dec. 8, 2022. [Online]. Available: https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf. [Accessed: 09-Jan-2026].

M. A. D. Varma, G. S. Vaasist, B. C. Reddy, M. P. Reddy, and R. Nair, “Intrusion detection system using signature and anomaly based algorithm,” 2025 International Conference on Inventive Computation Technologies (ICICT), Kirtipur, Nepal, 2025, pp. 838–842, doi: 10.1109/ICICT64420.2025.11004762.

K. Mithran and C. Gopi, “Anomaly detection in IoT sensor networks using machine learning,” 2022 International Conference on Computing, Communication, Security and Intelligent Systems (IC3SIS), Kochi, India, 2022, pp. 1–7, doi: 10.1109/IC3SIS54991.2022.9885575.

K. Mani and A. K. B. Shenoy, “Machine learning models in Web applications: A comprehensive review,” ICT Express, vol. 11, no. 6, 2025, pp. 1110–1119, ISSN 2405-9595, https://doi.org/10.1016/j.icte.2025.09.001.

D. Lu, J. Fei, and L. Liu, “A semantic learning-based SQL injection attack detection technology,” Electronics, vol. 12, p. 1344, 2023. https://doi.org/10.3390/electronics12061344.

R.-T. Lo, W.-J. Hwang, and T.-M. Tai, “SQL injection detection based on lightweight multi-head self-attention,” Applied Sciences, vol. 15, no. 2, p. 571, 2025. https://doi.org/10.3390/app15020571.

C. Caudill and D. Sury, “Visualize AI/ML model results using Flask and AWS Elastic Beanstalk,” Amazon Web Services (AWS) Prescriptive Guidance, [Online]. Available: https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/visualize-ai-ml-model-results-using-flask-and-aws-elastic-beanstalk.html. [Accessed: Mar. 21, 2026]..

G. Lazrek, K. Chetioui, Y. Balboul, S. Mazer, and M. El Bekkali, “An RFE/Ridge-ML/DL based anomaly intrusion detection approach for securing IoMT system”, Results in Engineering, vol. 23, p. 102659, 2024. https://doi.org/10.1016/j.rineng.2024.102659.

A. Rao, D. Khankhoje, U. Namdev, C. Bhadane, and D. Dongre, “Insights into NoSQL databases using financial data: A comparative analysis,” Procedia Comput. Sci., vol. 215, pp. 8–23, 2022.

K. S. Fathi, S. Barakat, and A. Rezk, “An effective SQL injection detection model using LSTM for imbalanced datasets,” Computers & Security, vol. 153, p. 104391, 2025. https://doi.org/10.1016/j.cose.2025.104391.

A. A. Mustapha, A. S. Udeh, T. A. Ashi, O. S. Sobowale, M. J. Akinwande, and A. O. Oteniara, “Comprehensive review of machine learning models for SQL injection detection in e-commerce,” World Journal of Advanced Research and Reviews, vol. 23, no. 1, pp. 451–465, July 2024, doi: 10.30574/wjarr.2024.23.1.2004.

S. Pasini et al., “Evaluating and improving the robustness of security attack detectors generated by LLMs,” Empirical Software Engineering, vol. 31, no. 2, p. 35, 2026.

N. S. Dasari et al., “Enhancing SQL injection detection and prevention using generative models,” 2025. arXiv:2502.04786.

J. Zulu, B. Han, I. Alsmadi, and G. Liang, “Enhancing machine learning based SQL injection detection using contextualized word embedding.” Proceedings of the 2024 ACM Southeast Conference (ACMSE ’24). Association for Computing Machinery, New York, NY, USA, pp. 211–216, 2024. https://doi.org/10.1145/3603287.3651187.

H. Sun, Y. Du, and Q. Li, “Deep learning-based detection technology for SQL injection research and implementation,” Appl. Sci., vol. 13, p. 9466, 2023. https://doi.org/10.3390/app13169466.

M. Alghawazi, D. Alghazzawi, and S. Alarifi, “Deep learning architecture for detecting SQL injection attacks based on RNN autoencoder model,” Mathematics, vol. 11, no. 15, p. 3286, 2023. https://doi.org/10.3390/math11153286.

M. Alghawazi, D. Alghazzawi, and S. Alarifi, “Detection of SQL injection attack using machine learning techniques: A systematic literature review,” Journal of Cybersecurity and Privacy, vol. 2, no. 4, pp. 764–777, 2022. https://doi.org/10.3390/jcp2040039.

F. K. Alarfaj and N. A. Khan, “Enhancing the performance of SQL injection attack detection through probabilistic neural networks,” Applied Sciences, vol. 13, no. 7, p. 4365, 2023. https://doi.org/10.3390/app13074365.

H. Xu, G. Pang, Y. Wang, and Y. Wang, “Deep Isolation Forest for anomaly detection,” IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 12, pp. 12591–12604, 2023.

A. Paul, V. Sharma, and O. Olukoya, “SQL injection attack: Detection, prioritization & prevention,” Journal of Information Security and Applications, vol. 85, p. 103871, 2024. https://doi.org/10.1016/j.jisa.2024.103871.

G. Floris et al., “ModSec-AdvLearn: Countering adversarial SQL injections with robust machine learning,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 6693–6705, 2025, doi: 10.1109/TIFS.2025.3583234.

K. Tasdemir, R. Khan, F. Siddiqui, S. Sezer, F. Kurugollu, S. B. Yengec-Tasdemir, and A. Bolat, “Advancing SQL injection detection for high-speed data centers: A novel approach using cascaded NLP,” 2023, arXiv:2312.13041.

D. Muduli et al., “SIDNet: A SQL injection detection network for enhancing cybersecurity,” IEEE Access, vol. 12, pp. 176511–176526, 2024, doi: 10.1109/ACCESS.2024.3502293.

N. Gandhi, J. Patel, R. Sisodiya, N. Doshi, and S. Mishra, “A CNN-BiLSTM based approach for detection of SQL injection attacks,” 2021 International Conference on Computational Intelligence and Knowledge Economy (ICCIKE), Dubai, United Arab Emirates, pp. 378–383, 2021, doi: 10.1109/ICCIKE51210.2021.9410675.

Z. Gui, E. Wang, B. Deng, M. Zhang, Y. Chen, S. Wei, W. Xie, and B. Wang, “SqliGPT: Evaluating and Utilizing Large Language Models for Automated SQL Injection Black-Box Detection” Applied Sciences, vol. 14, no. 16, p. 6929, 2024. https://doi.org/10.3390/app14166929.

Z. Xia, J. Shao, L. Yu, J. Sun, X. Yang, H. Xu, C. Liu, and J. Ren, “SQL injection attack detection method based on textCNN,” Proc. SPIE 13222, International Conference on Signal Processing and Communication Security (ICSPCS 2024), 1322219 (22 July 2024). https://doi.org/10.1117/12.3038647.

N. Thalji, A. Raza, M. S. Islam, N. A. Samee, and M. M. Jamjoom, “AE-Net: Novel autoencoder-based deep features for SQL injection attack detection,” IEEE Access, vol. 11, pp. 135507–135516, 2023, doi: 10.1109/ACCESS.2023.3337645.

T.-T.-H. Le, Y. Hwang, C. Choi, R. W. Wardhani, D. S. C. Putranto, and H. Kim, “Enhancing structured query language injection detection with trustworthy ensemble learning and boosting models using local explanation techniques,” Electronics vol. 13, no. 22, p. 4350, 2024. https://doi.org/10.3390/electronics13224350.

Sajid576, “SQL Injection Dataset,” Kaggle, 2021. [Online]. Available: https://www.kaggle.com/datasets/sajid576/sql-injection-dataset. [Accessed: 09-Jan-2026].

swisskyrepo, “PayloadsAllTheThings,” GitHub repository, 18 Oct. 2016-present. [Online]. Available: https://github.com/swisskyrepo/PayloadsAllTheThings. [Accessed: 09-Jan-2026].

capnmav77, “No-SQL_Gen: No-SQL Injection Dataset,” GitHub repository, 17 Aug. 2023. [Online]. Available: https://github.com/capnmav77/No-SQL_Gen. [Accessed: 09-Jan-2026].

OWASP, “SQL Injection Prevention Cheat Sheet,” OWASP Cheat Sheet Series, 2025. [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html. [Accessed: 09-Jan-2026].

OWASP, “Query Parameterization Cheat Sheet,” OWASP Cheat Sheet Series, 2025. [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/Query_Parameterization_Cheat_Sheet.html. [Accessed: 09-Jan-2026].

PortSwigger Ltd., “Burp Suite: Web application security testing software,” 2003-present. [Online]. Available: https://portswigger.net/burp. [Accessed: 09-Jan-2026].

sqlmap “Automatic SQL injection and database takeover tool sqlmap.org,” 2006-present. [Online]. Available: https://sqlmap.org/. [Accessed: 09-Jan-2026].

Pandas Development Team, “Pandas: Python Data Analysis Library,” 2008-present. [Online]. Available: https://pandas.pydata.org/. [Accessed: 09-Jan-2026].

NumPy Developers, “NumPy,” 2006-present. [Online]. Available: https://numpy.org/. [Accessed: 09-Jan-2026].

Python Software Foundation, “re — Regular expression operations,” Python 3. [Online]. Available: https://docs.python.org/3/library/re.html. [Accessed: 09-Jan-2026].

Python Software Foundation, “base64 – Encode and decode with base64,” Python 3. [Online]. Available: https://docs.python.org/3/library/base64.html. [Accessed: 09-Jan-2026].

Python Software Foundation, “urllib.parse – Parse URLs into components,” Python 3. [Online]. Available: https://docs.python.org/3/library/urllib.parse.html. [Accessed: 09-Jan-2026].

Python Software Foundation, “random – Generate pseudo-random numbers,” Python 3. [Online]. Available: https://docs.python.org/3/library/random.html. [Accessed: 09-Jan-2026].

Python Software Foundation, “collections – Container datatypes: Counter class,” Python 3. [Online]. Available: https://docs.python.org/3/library/collections.html#collections.Counter. [Accessed: 09-Jan-2026].

JSON:API, “Implementations,” 2025. [Online]. Available: https://jsonapi.org/implementations/. [Accessed: 09-Jan-2026].

“Nested objects in real apps,” freeCodeCamp Forum, Jul. 8, 2022. [Online]. Available: https://forum.freecodecamp.org/t/nested-objects-in-real-apps/526638. [Accessed: 09-Jan-2026].

“sqlparse,” PyPI, 2025. [Online]. Available: https://pypi.org/project/sqlparse/. [Accessed: 09-Jan-2026].

JSON Schema, “Documentation,” 2025. [Online]. Available: https://json-schema.org/docs. [Accessed: 09-Jan-2026].

Scikit-Learn Developers, “scikit-learn: Machine Learning in Python,” 2007-present. [Online]. Available: https://scikit-learn.org/stable/. [Accessed: 09-Jan-2026].

S. Xia, F. Zhang, and C. Zhang, “A Gradient Boosting based classification technique for assisted prediction algorithm research,” 2023 IEEE International Conference on Image Processing and Computer Applications (ICIPCA), Changchun, China, pp. 371–375, 2023, doi: 10.1109/ICIPCA59209.2023.10257866.

J. K. Jaiswal and R. Samikannu, “Application of Random Forest algorithm on feature subset selection and classification and regression,” 2017 World Congress on Computing and Communication Technologies (WCCCT), Tiruchirappalli, India, pp. 65–68, 2017, doi: 10.1109/WCCCT.2016.25.

V. Madaan, N. Sharma, R. S. Bangari, and S. Aluvala, “Fraudulent job posting detection using Logistic Regression,” 2024 International Conference on Information Science and Communications Technologies (ICISCT), Seoul, Korea, Republic of, pp. 1–6, 2024, doi: 10.1109/ICISCT64202.2024.10956218.

Amriana, A. A. Ilham, A. Achmad, and Y. Yusran, “Ensemble soft-voting model for classification optimization of medicinal plants leaves,” 2023 IEEE International Conference on Communication, Networks and Satellite (COMNETSAT), Malang, Indonesia, pp. 147–152, 2023, doi: 10.1109/COMNETSAT59769.2023.10420635.

V. Agate, A. De Paola, S. Drago, P. Ferraro, and G. L. Re, “Enhancing IoT network security with concept drift-aware unsupervised threat detection,” 2024 IEEE Symposium on Computers and Communications (ISCC), Paris, France, pp. 1–6, 2024, doi:10.1109/ISCC61673.2024.10733733.

OWASP Core Rule Set (CRS), “OWASP CRS Project – The 1st Line of Defense,” OWASP Foundation. [Online]. Available: https://coreruleset.org/. [Accessed: Jun. 3, 2026].

H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” Proc. 20th International Conf. on Artificial Intelligence and Statistics (AISTATS), Fort Lauderdale, FL, vol. 54, pp. 1273–1282, 2017.

R. F. Sidik, S. N. Yutia, and R. Z. Fathiyana, “The effectiveness of parameterized queries in preventing,” Proceedings of the International Conference on Enterprise and Industrial Systems (ICOEINS 2023), Cham, Switzerland: Springer Nature, p. 204, 2023.

J. Clarke, SQL Injection Attacks and Defense, 2nd ed. Burlington, MA, USA: Syngress/Elsevier, 2012.

C. Bauer and G. King, Java Persistence with Hibernate, 2nd ed. Shelter Island, NY, USA: Manning Publications, 2015.

M. Howard and D. LeBlanc, Writing Secure Code, 2nd ed. Redmond, WA, USA: Microsoft Press, 2003.

Oracle Corporation, Oracle Database Security Guide. Austin, TX, USA: Oracle Corporation, 2024.

C. Richardson, Microservices Patterns: With Examples in Java. Shelter Island, NY, USA: Manning Publications, 2018.

F. Pezoa, J. L. Reutter, F. Suárez, M. Ugarte, and D. Vrgoč, “Foundations of JSON Schema,” Proc. 25th Int. Conf. World Wide Web (WWW), Montréal, QC, Canada, pp. 263–273, 2016.

I. Ristić, ModSecurity Handbook: The Complete Guide to the Popular Open Source Web Application Firewall. London: Feisty Duck, 2023.

R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” Proc. IEEE Symp. Security and Privacy, Berkeley, CA, USA, pp. 305–316, 2010.

A. K. Mousa and M. N. Abdullah, “An improved deep learning model for DDoS detection based on hybrid stacked autoencoder and checkpoint network,” Future Internet, vol. 15, no. 8, art. no. 278, 2023, doi: 10.3390/fi15080278. [Online]. Available: https://www.mdpi.com/1999-5903/15/8/278. [Accessed: 09-Jan-2026].

Downloads

Published

2026-07-21

How to Cite

Shetty, N. P. ., Kothari, V. ., Shah, E. H. ., Kumar, P. J. ., & Shetty, J. . (2026). Detection and Mitigation of SQL Injection-based Attacks in Web Security. Journal of Mobile Multimedia, 22(03), 373–412. https://doi.org/10.13052/jmm1550-4646.2234

Issue

Section

Articles

Most read articles by the same author(s)