Nilima D. Bobade,
Swati S. Shereker,
- Assistant professor, Department, Computer Science, Sant Gadge Baba Amravati University, Maharashtra, India
- Assistant professor, Department, Computer Science, Sant Gadge Baba Amravati University, Maharashtra, India
Abstract
The rapid evolution and widespread adoption of the internet have significantly transformed the world, leading to an increased number of cyberattacks. Cybersecurity has become one of the most critical challenges for society, incurring substantial financial losses annually. This research focuses on SQL injection attacks, the specific threat to web applications, aiming to detect malicious queries designed to exploit vulnerabilities and access sensitive data. In recent years, the frequency of SQLi attacks has surged, posing severe risks to web application security. Attackers use SQLi to execute arbitrary SQL code, potentially gaining unauthorized access to databases, exfiltrating data, and compromising the integrity of web services. Despite various efforts to mitigate SQLi attacks, a comprehensive and effective detection mechanism remains elusive. This paper highlights the machine learning approach to identify and prevent SQLi attacks, providing a comparative analysis of various classifiers and their performance. The study underscores the potential of machine learning in enhancing web application security, offering adaptive and dynamic solutions to combat the evolving threat of SQLi attacks.
Keywords: Cyber security, machine learning, SQL injection, threat detection, web security
[This article belongs to International Journal of Information Security Engineering ]
Nilima D. Bobade, Swati S. Shereker. Securing Web Applications: A Machine Learning Approach for SQL Injection Threats. International Journal of Information Security Engineering. 2026; 04(01):16-22.
Nilima D. Bobade, Swati S. Shereker. Securing Web Applications: A Machine Learning Approach for SQL Injection Threats. International Journal of Information Security Engineering. 2026; 04(01):16-22. Available from: https://journals.stmjournals.com/ijise/article=2026/view=239123
References
- Brindavathi B, Karrothu A, Anilkumar C. An analysis of AI-based SQL injection (SQLi) attack detection. 2023 Second International Conference on Augmented Intelligence and Sustainable Systems (ICAISS), Trichy, India. 2023. p. 31–35. doi:10.1109/ICAISS58487.2023.10250505.
- Hasan M, Balbahaith Z, Tarique M. Detection of SQL injection attacks: a machine learning approach. 2019 International Conference on Electrical and Computing Technologies and Applications (ICECTA), Ras Al Khaimah, United Arab Emirates. 2019. p. 1–6. doi:10.1109/ICECTA48151.2019.8959617.
- Uwagbole SO, Buchanan WJ, Fan L. Applied machine learning predictive analytics to SQL injection attack detection and prevention. 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), Lisbon, Portugal. 2017. p. 1087–1090. doi:10.23919/INM.2017.7987433.
- Valli Kumari V, Prasanna Kumar Y. SQL injection detection using recurrent neural networks (RNN). In: Mesnager S, Stănică P, Debnath SK, editors. Security and Privacy. ICSP 2024. Communications in Computer and Information Science. Cham: Springer; 2025. p. 154–167. doi:10.1007/978-3-031-90587-2_11.
- Gogoi B, Ahmed T, Dutta A. Defending against SQL injection attacks in web applications using machine learning and natural language processing. 2021 IEEE 18th India Council International Conference (INDICON), Guwahati, India. 2021. p. 1–6. doi:10.1109/INDICON52576.2021.9691740.
- Roy P, Kumar R, Rani P. SQL injection attack detection by machine learning classifier. 2022 International Conference on Applied Artificial Intelligence and Computing (ICAAIC), Salem, India. 2022. p. 394–400. doi:10.1109/ICAAIC53929.2022.9792964.
- Alkhathami JM, Alzahrani SM. Detection of SQL injection attacks using machine learning in cloud computing platform. J Theor Appl Inf Technol. 2022;100(15):1–4.
- Ashlam AA, Badii A, Stahl F. A novel approach exploiting machine learning to detect SQLi attacks. 2022 5th International Conference on Advanced Systems and Emergent Technologies (IC_ASET), Hammamet, Tunisia. 2022. p. 513–517. doi:10.1109/IC_ASET53395.2022.9765948.
- Muliono Y, Darus MY, Pardomuan CR, Ariffin MAM, Kurniawan A. Predicting confidentiality, integrity, and availability from SQL injection payload. 2022 International Conference on Information Management and Technology (ICIMTech), Semarang, Indonesia. 2022. p. 600–605. doi:10.1109/ICIMTech55957.2022.9915227.
- Zhumabekova A, Matson ET, Karyukin V, Zhumabekova K, Zhuandykov B, Ussatova O, Telbayeva T. Determining web application vulnerabilities using machine learning methods. 2023 19th International Asian School-Seminar on Optimization Problems of Complex Systems (OPCS), Novosibirsk, Moscow, Russian Federation. 2023. p. 136–139. doi:10.1109/OPCS59592.2023.10275756.
- Zhang S, Li Y, Jiang Q. Feature ratio method: a payload feature extraction and detection approach for SQL injection attacks. 2023 3rd Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS), Shenyang, China. 2023. p. 172–175. doi:10.1109/ACCTCS58815.2023.00019.

International Journal of Information Security Engineering
| Volume | 04 |
| Issue | 01 |
| Received | 12/05/2025 |
| Accepted | 08/07/2025 |
| Published | 24/03/2026 |
| Publication Time | 316 Days |
Login
PlumX Metrics