[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123808-en":3,"doc-seo-123808-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123808,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",6,"Technology","Detecting SQL Injection Attacks by Binary Gray Wolf Optimizer and Machine Learning Algorithms","SQL injection is a critical web application security weakness because it enables attackers to manipulate database queries and obtain unauthorized access or data changes. This study presents an ML-based detection approach that depends on selecting the most effective features to train an optimal classifier. Feature selection is formulated as an NP-complete combinatorial optimization problem, addressed via two binary Gray-Wolf algorithm variants over a 13-feature dataset. Experiments show 99.68% accuracy, 99.40% precision, and 98.72% sensitivity, with detection efficiency improved by using only the top 20% features.","Neural Computing and Applications  \n[https://doi.org/10.1007/s00521-024-09429-z](https://doi.org/10.1007/s00521-024-09429-z)  \nDetecting SQL injection attacks by binary gray wolf optimizerand machine learning algorithms  \nBahman Arasteh1,6  • Babak Aghaei2 • Behnoud Farzad3 • Keyvan Arasteh1 • Farzad Kiani4 • Mahsa Torkamanian-Afshar5  \nReceived: 27 July 2023/Accepted: 15 January 2024  \n􀀂 The Author(s) 2024  \nAbstract  \nSQL injection is one of the important security issues in web applications because it allows an attacker to interact with the application’s database. SQL injection attacks can be detected using machine learning algorithms. The effective features should be employed in the training stage to develop an optimal classiﬁer with optimal accuracy. Identifying the most effective features is an NP-complete combinatorial optimization problem. Feature selection is the process of selecting the training dataset’s smallest and most effective features. The main objective of this study is to enhance the accuracy, precision, and sensitivity of the SQLi detection method. In this study, an effective method to detect SQL injection attacks has been proposed. In the ﬁrst stage, a speciﬁc training dataset consisting of 13 features was prepared. In the second stage, two different binary versions of the Gray-Wolf algorithm were developed to select the most effective features of the dataset. The created optimal datasets were used by different machine learning algorithms. Creating a new SQLi training dataset with 13 numeric features, developing two different binary versions of the gray wolf optimizer to optimally select the features of the dataset, and creating an effective and efﬁcient classiﬁer to detect SQLi attacks are the main contributions of this study. The results of the conducted tests indicate that the proposed SQL injection detector obtain 99.68% accuracy, 99.40% precision, and 98.72% sensitivity. The proposed method increases the efﬁciency of attack detection methods by selecting 20% of the most effective features.  \nKeywords Software security 􀀂 SQL injection attacks 􀀂 Artiﬁcial neural network 􀀂 Feature selection 􀀂 Binary gray wolf optimization algorithm 􀀂 Accuracy  \n& Bahman Arasteh [Bahman.arasteh@istinye.edu.tr](Bahman.arasteh@istinye.edu.tr)  \n1 Department of Software Engineering, Faculty of Engineering and Natural Science, Istinye University, Istanbul, Turkey  \n2 Department of Computer Engineering, Malekan Branch, Islamic Azad University, Malekan, Iran  \n3 Department of Computer Engineering, Seraj Institute, Tabriz, Azarbaijan Province, Iran  \n4 Data Science Application and Research Center (VEBIM), Fatih Sultan Mehmet Vakif University, Istanbul, Turkey  \n5 Computer Engineering Department, Faculty of Engineering, Istanbul Topkapi University, 34087 Istanbul, Turkey  \n6 Applied Science Research Center, Applied Science Private University, Amman, Jordan  \n1 Introduction  \nSoftware security is one of the major quality metrics of a software product [1] . SQL injection (SQLi) is one of the most serious software security concerns that any software development team should avoid. SQLi is a web security ﬂaw that allows an attacker to interact with database queries made by an application. SQL injection attacks are just malicious queries that change a typical SQL command into a malicious type. An attacker can directly use SQL queries to fetch information from databases to receive unlimited data and unauthorized access. In this attack, an attacker can alter or remove the data stored in the database using only a web browser. An attacker can escalate a SQL injection attack to compromise the underlying server or other back-end infrastructure or launch a denial-of-service attack in speciﬁc circumstances. Regarding the reports by  \n1 3  \nthe open worldwide application security project (OWASP), the vulnerability of SQL injection attacks is among the top 10 web application security risks [1–3] .  \nIn most web applications, ﬁltering techniques a","cbCaiu1KA9SQhD9g","https://ap.wps.com/l/cbCaiu1KA9SQhD9g","pdf",2178695,1,22,"English","en",105,"# Introduction\n## Software security and SQL injection risk\n## Machine learning-based SQLi detection\n## Feature selection as NP-complete optimization","[{\"question\":\"Why is SQL injection considered a major security issue?\",\"answer\":\"SQL injection allows attackers to alter legitimate SQL commands into malicious queries, enabling unauthorized data access, data modification, and potentially broader server compromise or denial-of-service.\"},{\"question\":\"How does the proposed method detect SQL injection attacks?\",\"answer\":\"It trains machine learning classifiers using an optimized feature subset. The approach prepares a 13-feature training dataset and applies two binary versions of the Gray-Wolf optimizer to select the most effective features before classification.\"},{\"question\":\"What results does the study report for the detector’s performance?\",\"answer\":\"The reported test outcomes are 99.68% accuracy, 99.40% precision, and 98.72% sensitivity. The method also improves efficiency by selecting about 20% of the most effective features.\"}]","Detecting SQL Injection Attacks by Binary Gray Wolf Optimizer and Machine Learning Algorithms | PDF",1785818664,55,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-sql-injection-attacks-by-binary-gray-wolf-optimizer-and-machine-learning-algorithms","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/detecting-sql-injection-attacks-by-binary-gray-wolf-optimizer-and-machine-learning-algorithms/123808/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is SQL injection considered a major security issue?","Question",{"text":75,"@type":76},"SQL injection allows attackers to alter legitimate SQL commands into malicious queries, enabling unauthorized data access, data modification, and potentially broader server compromise or denial-of-service.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed method detect SQL injection attacks?",{"text":80,"@type":76},"It trains machine learning classifiers using an optimized feature subset. The approach prepares a 13-feature training dataset and applies two binary versions of the Gray-Wolf optimizer to select the most effective features before classification.",{"name":82,"@type":73,"acceptedAnswer":83},"What results does the study report for the detector’s performance?",{"text":84,"@type":76},"The reported test outcomes are 99.68% accuracy, 99.40% precision, and 98.72% sensitivity. The method also improves efficiency by selecting about 20% of the most effective features.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]