维普中文期刊产品整合服务

Injections Attacks Efficient and Secure Techniques Based on Bidirectional Long Short Time Memory Model

查看全文 作  者:Abdulgbar [1]A.R.Farea;Gehad Abdullah [2]Amran;Ebraheem [3]Farea;Amerah [4]Alabrah;Ahmed [5]A.Abdulraheem;Muhammad [6]Mursil;Mohammed A.A.Al-[7]qaness 高影响力作者 机构地区:[1]School of Big Data&Software Engineering,Chongqing University,Chongqing,401331,China;[2]Department of Management Science Engineering,Dalian University of Technology,Dalian,116024,China;[3]Software College,Northeastern University,Shenyang,110169,China;[4]Department of Information Systems,College of Computer and Information Science,King Saud University,Riyadh,11543,Saudi Arabia;[5]Department of Management Science and Engineering,South China University of Technology,Guangzhou,510641,China;[6]Department of Computer Engineering and Mathematics,University of Rovira i Virgili,Tarragona,Spain;[7]College of Physics and Electronic Information Engineering,Zhejiang Normal University,Jinhua,321004,China高影响力机构 出  处:《Computers, Materials & Continua》索引2023年第76卷第9期,共18页高影响力期刊 基  金:funded byResearchers Supporting Project Number(RSP2023R476);King Saud University,Riyadh,Saudi Arabia。 摘  要:E-commerce,online ticketing,online banking,and other web-based applications that handle sensitive data,such as passwords,payment information,and financial information,are widely used.Various web developers may have varying levels of understanding when it comes to securing an online application.Structured Query language SQL injection and cross-site scripting are the two vulnerabilities defined by the OpenWeb Application Security Project(OWASP)for its 2017 Top Ten List Cross Site Scripting(XSS).An attacker can exploit these two flaws and launch malicious web-based actions as a result of these flaws.Many published articles focused on these attacks’binary classification.This article described a novel deep-learning approach for detecting SQL injection and XSS attacks.The datasets for SQL injection and XSS payloads are combined into a single dataset.The dataset is labeledmanually into three labels,each representing a kind of attack.This work implements some pre-processing algorithms,including Porter stemming,one-hot encoding,and the word-embedding method to convert a word’s text into a vector.Our model used bidirectional long short-term memory(BiLSTM)to extract features automatically,train,and test the payload dataset.The payloads were classified into three types by BiLSTM:XSS,SQL injection attacks,and normal.The outcomes demonstrated excellent performance in classifying payloads into XSS attacks,injection attacks,and non-malicious payloads.BiLSTM’s high performance was demonstrated by its accuracy of 99.26%. 关 键 词:Web security SQL injection XSS deep learning RNN LSTM BiLSTM
相关文献

参考文献(31)

引证文献(1)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费