{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T10:59:56Z","timestamp":1777805996719,"version":"3.51.4"},"reference-count":51,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2016,6,6]],"date-time":"2016-06-06T00:00:00Z","timestamp":1465171200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2016,8,16]]},"abstract":"<jats:p>SQL injection attack has been a major security threat to web applications for over a decade. Now a days, attackers use automated tools to discover vulnerable websites from search engines and launch attacks on multiple websites simultaneously. Being extremely heterogeneous in nature, accurate run-time detection of SQL injection attacks, particularly those previously unseen, is still a challenge using regular-expression or parse-tree matching techniques suggested in the literature. In this paper, we present a novel approach for real-time detection of SQL injection attacks by applying document similarity measure on run-time queries after normalizing them into sentence-like form. The proposed approach acts as a database firewall and can protect multiple web applications using the database server. With additional inputs from human expert, the system can also become more robust over time. We implemented the approach in a tool named SQLiDDS and the experimental results are very encouraging. The approach can effectively detect all types of SQL injection attacks and previously unseen attacks with substantial accuracy yet negligible impact on overall performance of web applications. The tool was built with PHP and tested on web applications built with PHP and MySQL, but it can be adapted to other platforms with minimal changes.<\/jats:p>","DOI":"10.3233\/jcs-160554","type":"journal-article","created":{"date-parts":[[2016,8,23]],"date-time":"2016-08-23T10:44:17Z","timestamp":1471949057000},"page":"507-539","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":6,"title":["SQLiDDS: SQL injection detection using document similarity measure"],"prefix":"10.1177","volume":"24","author":[{"given":"Debabrata","family":"Kar","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Silicon Institute of Technology, Bhubaneswar,\u00a0India. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suvasini","family":"Panigrahi","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, VSS University of Technology, Burla,\u00a0Sambalpur,\u00a0India. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Srikanth","family":"Sundararajan","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology, Bhubaneswar, India. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2016,6,6]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"C.C.\u00a0Aggarwal and C.\u00a0Zhai, A survey of text clustering algorithms, in: Mining Text Data, Springer, 2012, pp.\u00a077\u2013128. doi:10.1007\/978-1-4614-3223-4_4.","DOI":"10.1007\/978-1-4614-3223-4_4"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.5120\/906-1283"},{"key":"ref003","unstructured":"M.\u00a0Benedikt, J.\u00a0Freire and P.\u00a0Godefroid, VeriWeb: Automatically testing dynamic web sites, in: Proceedings of the 11th International World Wide Web Conference (WWW\u20192002), 2002."},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"P.\u00a0Bisht, P.\u00a0Madhusudan and V.\u00a0Venkatakrishnan, CANDID: Dynamic candidate evaluations for automatic prevention of SQL injection attacks, ACM Transactions on Information and System Security (TISSEC) 13(2) (2010), 14.","DOI":"10.1145\/1698750.1698754"},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"S.\u00a0Boyd and A.\u00a0Keromytis, SQLrand: Preventing SQL injection attacks, in: Applied Cryptography and Network Security, Springer, 2004, pp.\u00a0292\u2013302. doi:10.1007\/978-3-540-24852-1_21.","DOI":"10.1007\/978-3-540-24852-1_21"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"G.\u00a0Buehrer, B.\u00a0Weide and P.\u00a0Sivilotti, Using parse tree validation to prevent SQL injection attacks, in: Proceedings of the 5th International Workshop on Software Engineering and Middleware, ACM, 2005, pp.\u00a0106\u2013113. doi:10.1145\/1108473.1108496.","DOI":"10.1145\/1108473.1108496"},{"key":"ref007","doi-asserted-by":"publisher","DOI":"10.1016\/j.cor.2004.03.019"},{"key":"ref008","doi-asserted-by":"crossref","unstructured":"J.\u00a0Choi, H.\u00a0Kim, C.\u00a0Choi and P.\u00a0Kim, Efficient malicious code detection using N-gram analysis and SVM, in: 2011 International Conference on Network-Based Information Systems (NBiS), IEEE, 2011, pp.\u00a0618\u2013621.","DOI":"10.1109\/NBiS.2011.104"},{"key":"ref009","doi-asserted-by":"crossref","unstructured":"M.\u00a0Cova, D.\u00a0Balzarotti, V.\u00a0Felmetsger and G.\u00a0Vigna, Swaddler: An approach for the anomaly-based detection of state violations in web applications, in: Recent Advances in Intrusion Detection, Springer, 2007, pp.\u00a063\u201386. doi:10.1007\/978-3-540-74320-0_4.","DOI":"10.1007\/978-3-540-74320-0_4"},{"key":"ref010","unstructured":"S.\u00a0Curtis, Barclays: 97 percent of data breaches still due to SQL injection, 2012, available at: http:\/\/news.techworld.com\/security\/3331283\/barclays-97-percent-of-data-breaches-still-due-to-sql-injection\/."},{"key":"ref011","unstructured":"J.\u00a0Dahse, Exploiting hard filtered SQL Injections, 2010, available at: http:\/\/websec.wordpress.com\/2010\/03\/19\/exploiting-hard-filtered-sql-injections\/. Accessed: 2011-06-23."},{"key":"ref012","doi-asserted-by":"publisher","DOI":"10.1162\/089976698300017197"},{"key":"ref013","unstructured":"F.\u00a0Donovan, SQL injection attacks: Stop the madness, 2014, available at: http:\/\/www.fierceitsecurity.com\/story\/sql-injection-attacks-stop-madness\/2014-03-04. Accessed: 2014-05-05."},{"key":"ref014","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2010.03.010"},{"key":"ref015","unstructured":"A.\u00a0Douglen, SQL smuggling, or, the attack that wasn\u2019t there, 2007, available at: https:\/\/dl.packetstormsecurity.net\/papers\/database\/SQL_Smuggling.pdf. Accessed: 2015-02-12."},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"B.\u00a0Gallagher and T.\u00a0Eliassi-Rad, Classification of HTTP attacks: A study on the ECML\/PKDD 2007 discovery challenge, in: Center for Advanced Signal and Image Sciences (CASIS) Workshop, 2008.","DOI":"10.2172\/1113394"},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2006.09.001"},{"key":"ref018","doi-asserted-by":"publisher","DOI":"10.1006\/cgip.1993.1040"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"W.\u00a0Halfond and A.\u00a0Orso, AMNESIA: Analysis and monitoring for NEutralizing SQL-injection attacks, in: Proceedings of the 20th IEEE\/ACM International Conference on Automated Software Engineering, ACM, 2005, pp.\u00a0174\u2013183. doi:10.1145\/1101908.1101935.","DOI":"10.1145\/1101908.1101935"},{"key":"ref020","unstructured":"W.\u00a0Halfond, J.\u00a0Viegas and A.\u00a0Orso, A classification of SQL-injection attacks and countermeasures, in: International Symposium on Secure Software Engineering (ISSSE), 2006, pp.\u00a012\u201323."},{"key":"ref021","unstructured":"L.\u00a0Hayek, Analysis of amphibian biodiversity data, in: Measuring and Monitoring Biological Diversity: Standard Methods for Amphibians, 1994, pp. 207\u2013270."},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"M.\u00a0Johns, C.\u00a0Beyerlein, R.\u00a0Giesecke and J.\u00a0Posegga, Secure code generation for web applications, in: Engineering Secure Software and Systems, 2010, pp. 96\u2013113. doi:10.1007\/978-3-642-11747-3_8.","DOI":"10.1007\/978-3-642-11747-3_8"},{"key":"ref023","doi-asserted-by":"crossref","unstructured":"S.\u00a0Kals, E.\u00a0Kirda, C.\u00a0Kruegel and N.\u00a0Jovanovic, Secubat: A web vulnerability scanner, in: Proceedings of the 15th International Conference on World Wide Web (WWW\u20192006), ACM, 2006, pp.\u00a0247\u2013256. doi:10.1145\/1135777.1135817.","DOI":"10.1145\/1135777.1135817"},{"key":"ref024","doi-asserted-by":"crossref","unstructured":"D.\u00a0Kar and S.\u00a0Panigrahi, Prevention of SQL injection attack using query transformation and hashing, in: Proceedings of the 3rd IEEE International Advance Computing Conference (IACC), IEEE, 2013, pp.\u00a01317\u20131323.","DOI":"10.1109\/IAdCC.2013.6514419"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"D.\u00a0Kar, S.\u00a0Panigrahi and S.\u00a0Sundararajan, SQLiDDS: SQL injection detection using query transformation and document similarity, in: Distributed Computing and Internet Technology, Springer, 2015, pp.\u00a0377\u2013390.","DOI":"10.1007\/978-3-319-14977-6_41"},{"key":"ref026","unstructured":"S.M.\u00a0Kerner, How was SQL injection discovered? 2013, available at: http:\/\/www.esecurityplanet.com\/network-security\/how-was-sql-injection-discovered.html. Accessed: 2013-12-12."},{"key":"ref027","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.02.041"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"R.\u00a0Kozik and M.\u00a0Chora\u015b, Machine learning techniques for cyber attacks detection, in: Image Processing and Communications Challenges 5, Springer, 2014, pp.\u00a0391\u2013398. doi:10.1007\/978-3-319-01622-1_44.","DOI":"10.1007\/978-3-319-01622-1_44"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.1016\/j.mcm.2011.01.050"},{"key":"ref030","unstructured":"Y.\u00a0Liao and V.R.\u00a0Vemuri, Using text categorization techniques for intrusion detection, in: USENIX Security Symposium, Vol.\u00a012, 2002, pp.\u00a051\u201359."},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"A.\u00a0Liu, Y.\u00a0Yuan, D.\u00a0Wijesekera and A.\u00a0Stavrou, SQLProb: A proxy-based architecture towards preventing SQL injection attacks, in: Proceedings of the 2009 ACM Symposium on Applied Computing, ACM, 2009, pp.\u00a02054\u20132061. doi:10.1145\/1529282.1529737.","DOI":"10.1145\/1529282.1529737"},{"key":"ref032","doi-asserted-by":"crossref","unstructured":"B.\u00a0Livshits and \u00da.\u00a0Erlingsson, Using web application construction frameworks to protect against code injection attacks, in: Proceedings of the 2007 Workshop on Programming Languages and Analysis for Security, ACM, 2007, pp.\u00a095\u2013104. doi:10.1145\/1255329.1255346.","DOI":"10.1145\/1255329.1255346"},{"key":"ref033","unstructured":"D.\u00a0Maciejak and G.\u00a0Lovet, Botnet-powered SQL injection attacks: A deeper look within, in: Virus Bulletin Conference, 2009, pp.\u00a0286\u2013288."},{"key":"ref034","unstructured":"C.D.\u00a0Manning, P.\u00a0Raghavan and H.\u00a0Sch\u00fctze, Introduction to Information Retrieval, Vol.\u00a01, Cambridge University Press, Cambridge, 2008, available at: http:\/\/nlp.stanford.edu\/IR-book\/pdf\/irbookonlinereading.pdf."},{"key":"ref035","unstructured":"O.\u00a0Maor and A.\u00a0Shulman, SQL injection signatures evasion, White paper, Imperva Inc., 2004, available at: http:\/\/www.issa-sac.org\/info_resources\/ISSA_20050519_iMperva_SQLInjection.pdf."},{"key":"ref036","doi-asserted-by":"crossref","unstructured":"R.\u00a0McClure and I.\u00a0Kruger, SQL DOM: Compile time checking of dynamic SQL statements, in: Proceedings of the 27th International Conference on Software Engineering (ICSE 2005), IEEE, 2005, pp.\u00a088\u201396.","DOI":"10.1109\/ICSE.2005.1553551"},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"A.\u00a0Nguyen-Tuong, S.\u00a0Guarnieri, D.\u00a0Greene, J.\u00a0Shirley and D.\u00a0Evans, Automatically hardening web applications using precise tainting, in: Security and Privacy in the Age of Ubiquitous Computing, 2005, pp.\u00a0295\u2013307.","DOI":"10.1007\/0-387-25660-1_20"},{"key":"ref038","unstructured":"OWASP, Top 10 security threats 2013, available at: https:\/\/www.owasp.org\/index.php\/Top_10_2013-A1-Injection. Accessed: 2013-11-15."},{"key":"ref039","unstructured":"S.\u00a0Quartini and M.\u00a0Rondini, Blind SQL injection with regular expressions attack, 2011, available at: http:\/\/www.ihteam.net\/papers\/blind-sqli-regexp-attack.pdf."},{"key":"ref040","unstructured":"RFP, NT web technology vulnerabilities, Phrack Magazine 8(54) (1998), 8, available at: http:\/\/phrack.org\/issues.html?issue=54&id=8#article."},{"key":"ref041","doi-asserted-by":"publisher","DOI":"10.1186\/2190-8532-1-1"},{"key":"ref042","unstructured":"S.\u00a0Small, J.\u00a0Mason, F.\u00a0Monrose, N.\u00a0Provos and A.\u00a0Stubblefield, To catch a predator: A natural language approach for eliciting malicious payloads, in: USENIX Security Symposium, 2008, pp.\u00a0171\u2013184."},{"key":"ref043","unstructured":"S.T.\u00a0Sun and K.B.\u00a0Sqlprevent, Effective dynamic detection and prevention of SQL injection attacks without access to the application source code, Technical report LERSSE-TR-2008-01, Laboratory for Education and Research in Secure Systems Engineering, University of British Columbia, 2008."},{"key":"ref044","unstructured":"TrustWave, Trustwave 2012 global security report, 2012, available at: https:\/\/www.trustwave.com\/global-security-report. Accessed: 2013-06-24."},{"key":"ref045","unstructured":"R.E.\u00a0Tulloss, Assessment of similarity indices for undesirable properties and a new tripartite similarity index based on cost functions, in: Mycology in Sustainable Development: Expanding Concepts, Vanishing Borders, 1997, pp. 122\u2013143."},{"key":"ref046","doi-asserted-by":"crossref","unstructured":"C.\u00a0Ulmer and M.\u00a0Gokhale, A configurable-hardware document-similarity classifier to detect web attacks, in: 2010 IEEE International Symposium on Parallel & Distributed Processing, Workshops and Phd Forum (IPDPSW), Vol.\u00a04, IEEE, 2010, pp.\u00a01\u20138.","DOI":"10.1109\/IPDPSW.2010.5470737"},{"key":"ref047","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2010.07.005"},{"key":"ref048","unstructured":"A.\u00a0Walenstein, M.\u00a0Venable, M.\u00a0Hayes, C.\u00a0Thompson and A.\u00a0Lakhotia, Exploiting similarity between variants to defeat malware, in: Proceedings of BlackHat 2007 DC Briefings, BlackHat, 2007."},{"key":"ref049","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Wang and Z.\u00a0Li, SQL injection detection via program tracing and machine learning, in: Internet and Distributed Computing Systems, Springer, 2012, pp.\u00a0264\u2013274. doi:10.1007\/978-3-642-34883-9_21.","DOI":"10.1007\/978-3-642-34883-9_21"},{"key":"ref050","doi-asserted-by":"crossref","unstructured":"G.\u00a0Wassermann, D.\u00a0Yu, A.\u00a0Chander, D.\u00a0Dhurjati, H.\u00a0Inamura and Z.\u00a0Su, Dynamic test input generation for web applications, in: Proceedings of the 2008 International Symposium on Software Testing and Analysis, ACM, 2008, pp.\u00a0249\u2013260.","DOI":"10.1145\/1390630.1390661"},{"key":"ref051","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Zhang, J.I.\u00a0Hong and L.F.\u00a0Cranor, CANTINA: A content-based approach to detecting phishing web sites, in: Proceedings of the 16th International Conference on World Wide Web (WWW\u20192007), ACM, 2007, pp.\u00a0639\u2013648. doi:10.1145\/1242572.1242659.","DOI":"10.1145\/1242572.1242659"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-160554","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-160554","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-160554","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:44:59Z","timestamp":1777495499000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-160554"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,6,6]]},"references-count":51,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2016,8,16]]}},"alternative-id":["10.3233\/JCS-160554"],"URL":"https:\/\/doi.org\/10.3233\/jcs-160554","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,6,6]]}}}