{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T12:55:59Z","timestamp":1782132959563,"version":"3.54.5"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T00:00:00Z","timestamp":1780012800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T00:00:00Z","timestamp":1780012800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Syst Assur Eng Manag"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s13198-026-03352-3","type":"journal-article","created":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T04:01:44Z","timestamp":1780027304000},"page":"1908-1920","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Query comparison engine to detect and prevent SQL injection attacks"],"prefix":"10.1007","volume":"17","author":[{"given":"Jayanto Kumar","family":"Chowdhury","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dilip Kumar","family":"Yadav","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"P. V. S. S. R. Chandra","family":"Mouli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,29]]},"reference":[{"key":"3352_CR1","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1016\/j.procs.2010.12.076","volume":"3","author":"ABM Ali","year":"2011","unstructured":"Ali ABM, Shakhatreh AI, Abdullah MS, Alostad J (2011) Sql-injection vulnerability scanning tool for automatic creation of sql-injection attacks. Procedia Computer Sci 3:453\u2013458","journal-title":"Procedia Computer Science"},{"key":"3352_CR2","doi-asserted-by":"crossref","unstructured":"Buehrer G, Weide BW, Sivilotti PA (2005) Using parse tree validation to prevent sql injection attacks. Proceedings of the 5th international workshop on software engineering and middleware. pp 106\u2013113","DOI":"10.1145\/1108473.1108496"},{"key":"3352_CR3","doi-asserted-by":"crossref","unstructured":"Chowdhury S, Nandi A, Ahmad M, Jain A, Pawar M (2021). A comprehensive survey for detection and prevention of sql injection. In: 2021 7th international conference on advanced computing and communication systems (ICACCS), 1, 434\u2013437 IEEE","DOI":"10.1109\/ICACCS51430.2021.9442012"},{"key":"3352_CR4","doi-asserted-by":"crossref","unstructured":"Cook WR, Rai S (2005) Safe query objects: statically typed objects as remotely executable queries. Proceedings of the 27th international conference on software engineering. pp 97\u2013106","DOI":"10.1109\/ICSE.2005.1553552"},{"key":"3352_CR5","doi-asserted-by":"crossref","unstructured":"Elia IA, Fonseca J, Vieira M (2010) Comparing sql injection detection tools using attack injection: An experimental study. In: 2010 IEEE 21st international symposium on software reliability engineering, 289\u2013298 IEEE","DOI":"10.1109\/ISSRE.2010.32"},{"key":"3352_CR6","doi-asserted-by":"crossref","unstructured":"Ghafarian A (2017) A hybrid method for detection and prevention of sql injection attacks. In: 2017 computing conference, 833\u2013838 IEEE","DOI":"10.1109\/SAI.2017.8252192"},{"key":"3352_CR7","doi-asserted-by":"crossref","unstructured":"Gould C, Su Z, Devanbu P (2004) Jdbc checker: A static analysis tool for sql\/jdbc applications. In: Proceedings. 26th international conference on software engineering, 697\u2013698 IEEE","DOI":"10.1109\/ICSE.2004.1317494"},{"key":"3352_CR8","unstructured":"Haldar V, Chandra D, Franz M (2005) Dynamic taint propagation for java. In: 21st annual computer security applications conference (ACSAC\u201905), 9 IEEE"},{"key":"3352_CR9","doi-asserted-by":"crossref","unstructured":"Huang Y-W, Huang S-K, Lin T-P, Tsai C-H (2003) Web application security assessment by fault injection and behavior monitoring. In: Proceedings of the 12th international conference on world wide web, pp. 148\u2013159","DOI":"10.1145\/775152.775174"},{"key":"3352_CR10","doi-asserted-by":"crossref","unstructured":"Hlaing ZCSS, Khaing M (2020) A detection and prevention technique on sql injection attacks. In: 2020 IEEE conference on computer applications (ICCA), pp. 1\u20136 IEEE","DOI":"10.1109\/ICCA49400.2020.9022833"},{"key":"3352_CR11","doi-asserted-by":"crossref","unstructured":"Halfond WG, Orso A (2005) Amnesia: analysis and monitoring for neutralizing sql-injection attacks. Proceedings of the 20th IEEE\/ACM international conference on automated software engineering. pp 174\u2013183","DOI":"10.1145\/1101908.1101935"},{"key":"3352_CR12","unstructured":"Holland CA (2019) ML-SQL-Injection-Detector. https:\/\/github.com\/ChrisAHolland\/ML-SQL-Injection-Detector\/tree\/master\/data"},{"issue":"1","key":"3352_CR13","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1109\/TSE.2007.70748","volume":"34","author":"W Halfond","year":"2008","unstructured":"Halfond W, Orso A, Manolios P (2008) Wasp: Protecting web applications using positive tainting and syntax-aware evaluation. IEEE Trans Software Eng 34(1):65\u201381","journal-title":"IEEE Trans Software Eng"},{"key":"3352_CR14","unstructured":"Jimoh A, Ahmed MK, Salihu S, Modi B, Salihu MN (2024) Enhancing web security through comprehensive evaluation of sql injection detection models. MakeLearn 2024: Artif Intell Human-Technol Sustain Dev"},{"key":"3352_CR15","doi-asserted-by":"crossref","unstructured":"Jana A, Maity D (2020) Code-based analysis approach to detect and prevent sql injection attacks. In: 2020 11th International Conference on Computing, Commun Networking Technol ICCCNT), 1\u20136 IEEE","DOI":"10.1109\/ICCCNT49239.2020.9225575"},{"issue":"3","key":"3352_CR16","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1002\/spy2.370","volume":"7","author":"A Kumar","year":"2024","unstructured":"Kumar A, Dutta S, Pranav P (2024) Analysis of sql injection attacks in the cloud and in web applications. Secur Priv 7(3):370","journal-title":"Security and Privacy"},{"key":"3352_CR17","doi-asserted-by":"publisher","first-page":"5565950","DOI":"10.1049\/2024\/5565950","volume":"1","author":"Y Liu","year":"2024","unstructured":"Liu Y (2024) Dai Y (2024) Deep learning in cybersecurity: A hybrid bert-lstm network for sql injection attack detection. IET Inf Secur 1:5565950","journal-title":"IET Inf Secur"},{"key":"3352_CR18","unstructured":"Livshits VB (2005) Finding security errors in java programs with static analysis. Proc. 14th USENIX Security Symposium"},{"issue":"1\u20132","key":"3352_CR19","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1016\/j.mcm.2011.01.050","volume":"55","author":"I Lee","year":"2012","unstructured":"Lee I, Jeong S, Yeo S, Moon J (2012) A novel method for sql injection attack detection based on removing sql query attribute values. Math Comput Model 55(1\u20132):58\u201368","journal-title":"Math Comput Model"},{"key":"3352_CR20","doi-asserted-by":"crossref","unstructured":"McClure RA, Kr\u00fcger IH (2005) Sql dom: compile time checking of dynamic sql statements. In: Proceedings of the 27th International conference on software engineering, 88\u201396","DOI":"10.1109\/ICSE.2005.1553551"},{"issue":"10","key":"3352_CR21","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1145\/1103845.1094840","volume":"40","author":"M Martin","year":"2005","unstructured":"Martin M, Livshits B, Lam MS (2005) Finding application errors and security flaws using pql: a program query language. Acm Sigplan Notices 40(10):365\u2013383","journal-title":"Acm Sigplan Notices"},{"key":"3352_CR22","doi-asserted-by":"crossref","unstructured":"Mishra A, Mehra N, Mishra J (2024) A novel technique for sql injection, detection and preventions using token separation. In: 2024 international conference on advances in computing research on science engineering and technology (ACROSET), 1\u20134 IEEE","DOI":"10.1109\/ACROSET62108.2024.10743869"},{"key":"3352_CR23","doi-asserted-by":"crossref","unstructured":"Mitropoulos D, Spinellis D (2009) Sdriver: Location-specific signatures prevent sql injection attacks. computers & security 28(3-4), 121\u2013129","DOI":"10.1016\/j.cose.2008.09.005"},{"key":"3352_CR24","doi-asserted-by":"publisher","first-page":"790","DOI":"10.1016\/j.protcy.2012.05.129","volume":"4","author":"K Natarajan","year":"2012","unstructured":"Natarajan K, Subramani S (2012) Generation of sql-injection free secure algorithm to detect and prevent sql-injection attacks. Procedia Technol 4:790\u2013796","journal-title":"Procedia Technol"},{"key":"3352_CR25","doi-asserted-by":"crossref","unstructured":"Nguyen-Tuong A, Guarnieri S, Greene D, Shirley J, Evans D (2005) Automatically hardening web applications using precise tainting. IFIP Int Inf Security Conf Springer, pp 295\u2013307","DOI":"10.1007\/0-387-25660-1_20"},{"key":"3352_CR26","doi-asserted-by":"crossref","unstructured":"Odumuyiwa V, Chibueze A (2020) Automatic detection of http injection attacks using convolutional neural network and deep neural network. J Cyber Security Mobility 489\u2013514","DOI":"10.13052\/jcsm2245-1439.941"},{"key":"3352_CR27","doi-asserted-by":"crossref","unstructured":"Pietraszek T, Berghe CV (2005) Defending against injection attacks through context-sensitive string evaluation. Int Workshop Recent Adv Intrusion Detection. Springer, pp 124\u2013145","DOI":"10.1007\/11663812_7"},{"key":"3352_CR28","doi-asserted-by":"crossref","unstructured":"Park J-C, Noh B-N (2006) Sql injection attack detection: profiling of web application parameter using the sequence pairwise alignment. Int Workshop Inf Security Appl Springer, pp 74\u201382","DOI":"10.1007\/978-3-540-71093-6_6"},{"key":"3352_CR29","doi-asserted-by":"crossref","unstructured":"Qbea\u2019h M, Alshraideh M, Sabri KE (2016) Detecting and preventing sql injection attacks: a formal approach. Cybersecurity and Cyberforensics Conference (CCC). pp 123\u2013129","DOI":"10.1109\/CCC.2016.26"},{"key":"3352_CR30","unstructured":"Stiawan D, Bardadi A, Afifah N, Melinda L, Heryanto A, Septian TW, Idris MY, Subroto IMI, Budiarto R et al.: (2023) An improved lstm-pca ensemble classifier for sql injection and xss attack detection. Computer Syst Sci Eng 46(2)"},{"key":"3352_CR31","doi-asserted-by":"crossref","unstructured":"Scott D, Sharp R (2002) Abstracting application-level web security. Proceedings of the 11th international conference on world wide web. pp 396\u2013407","DOI":"10.1145\/511446.511498"},{"issue":"1","key":"3352_CR32","doi-asserted-by":"publisher","first-page":"372","DOI":"10.1145\/1111320.1111070","volume":"41","author":"Z Su","year":"2006","unstructured":"Su Z, Wassermann G (2006) The essence of command injection attacks in web applications. Acm Sigplan Notices 41(1):372\u2013382","journal-title":"Acm Sigplan Notices"},{"key":"3352_CR33","doi-asserted-by":"publisher","first-page":"68633","DOI":"10.1109\/ACCESS.2022.3185748","volume":"10","author":"YE Seyyar","year":"2022","unstructured":"Seyyar YE, Yavuz AG, \u00dcnver HM (2022) An attack detection framework based on bert and deep learning. IEEE Access 10:68633\u201368644","journal-title":"IEEE Access"},{"issue":"3","key":"3352_CR34","doi-asserted-by":"publisher","first-page":"589","DOI":"10.1016\/j.infsof.2008.08.002","volume":"51","author":"S Thomas","year":"2009","unstructured":"Thomas S, Williams L, Xie T (2009) On automated prepared statement generation to remove sql injection vulnerabilities. Inf Softw Technol 51(3):589\u2013598","journal-title":"Inf Softw Technol"},{"key":"3352_CR35","doi-asserted-by":"crossref","unstructured":"Veerabudren KR, Bekaroo G (2022) Security in web applications: a comparative analysis of key sql injection detection techniques. 2022 4th international conference on emerging trends in electrical, electronic and communications engineering. ELECOM, pp 1\u20136","DOI":"10.1109\/ELECOM54934.2022.9965264"},{"key":"3352_CR36","unstructured":"Vishal B (2022) HttpParamsDataset: SQL injection detection dataset. https:\/\/github.com\/Vishal-B\/HttpParamsDataset"},{"key":"3352_CR37","doi-asserted-by":"crossref","unstructured":"Valeur F, Mutz D, Vigna G (2005) A learning-based approach to the detection of sql attacks. International conference on detection of intrusions and Malware, and vulnerability assessment. Springer, pp 123\u2013140","DOI":"10.1007\/11506881_8"},{"key":"3352_CR38","unstructured":"Wassermann G, Su Z (2004) An analysis framework for security in web applications. Proceedings of the FSE workshop on specification and verification of component-based systems. pp 70\u201378 (SAVCBS 2004)"},{"key":"3352_CR39","doi-asserted-by":"crossref","unstructured":"Xu J, Ni M, Zhu D, Yu X (2023) Overview of sql injection attack detection techniques. Proceedings of the 2023 international conference on communication network and machine learning. pp 215\u2013225","DOI":"10.1145\/3640912.3640956"},{"key":"3352_CR40","doi-asserted-by":"crossref","unstructured":"Xu N, Zhang D, Chen B, Ma H (2024) Research on sql injection detection method based on mixed word embedding. 2024 6th international conference on communications. information system and computer engineering (CISCE, pp 995\u2013998","DOI":"10.1109\/CISCE62493.2024.10653249"},{"issue":"18","key":"3352_CR41","doi-asserted-by":"publisher","first-page":"8365","DOI":"10.3390\/app14188365","volume":"14","author":"G-Y Yang","year":"2024","unstructured":"Yang G-Y, Wang F, Gu Y-Z, Teng Y-W, Yeh K-H, Ho P-H, Wen W-L (2024) Tpsqli: test prioritization for sql injection vulnerability detection in web applications. Appl Sci 14(18):8365","journal-title":"Appl Sci"},{"key":"3352_CR42","doi-asserted-by":"crossref","unstructured":"Zhang L, Gu Q, Peng S, Chen X, Zhao H, Chen D (2010) D-wav: A web application vulnerabilities detection tool using characteristics of web forms. In: 2010 fifth international conference on software engineering advances, 501\u2013507","DOI":"10.1109\/ICSEA.2010.85"},{"key":"3352_CR43","first-page":"4836289","volume":"1","author":"W Zhang","year":"2022","unstructured":"Zhang W, Li Y, Li X, Shao M, Mi Y, Zhang H (2022) Zhi G (2022) Deep neural network-based sql injection detection method. Security Commun Networks 1:4836289","journal-title":"Security and Communication Networks"},{"issue":"16","key":"3352_CR44","doi-asserted-by":"publisher","first-page":"2914","DOI":"10.3390\/math10162914","volume":"10","author":"C Zhao","year":"2022","unstructured":"Zhao C, Si S, Tu T, Shi Y, Qin S (2022) Deep-learning based injection attacks detection method for http. Mathematics 10(16):2914","journal-title":"Mathematics"}],"container-title":["International Journal of System Assurance Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-026-03352-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13198-026-03352-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-026-03352-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T12:41:40Z","timestamp":1782132100000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13198-026-03352-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,29]]},"references-count":44,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["3352"],"URL":"https:\/\/doi.org\/10.1007\/s13198-026-03352-3","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-4783414\/v1","asserted-by":"object"}]},"ISSN":["0975-6809","0976-4348"],"issn-type":[{"value":"0975-6809","type":"print"},{"value":"0976-4348","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,29]]},"assertion":[{"value":"25 July 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Thee authors assure that the results reported in this research has no conflict of interest with any authors.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}