DETECTING SQL INJECTION ATTACKS: A SYSTEMATIC SURVEY OF SIGNATURE, BEHAVIOR AND LEARNING-BASED METHODS

Authors

  • Maguluri V Lavanya Symbiosis Institute of Technology, Hyderabad, Telangana, India
  • Kranthi Kumar Singamaneni School of CS & AI, Research Supervisor, Symbiosis Institute of Technology, Hyderabad, Telangana, India.

DOI:

https://doi.org/10.70917/ijcisim-2026-2197

Keywords:

SQL Injection Detection, Web Application Security, Signature-Based Methods, Behavior Analysis, Machine Learning, Deep Learning, Hybrid Frameworks, Intrusion Detection, Cybersecurity, Threat Mitigation

Abstract

SQL Injection (SQLi) is classified as a high priority security vulnerability that affects dynamic web applications and Database-Driven Systems (DBDS). Despite a marked improvement in Defensive Programming and Automated Testing, attackers have continued to find ways to exploit logical errors in Query Construction to gain unauthorized access to DBDS and to manipulate Data. This paper presents a Systematic Review of SQL Injection Detection Techniques, which are categorized using three (3) different approaches - Signature-Based, Behaviour-Based and Learning-Based. This Review identifies and compares all the articles published between 2013 and 202035 in the leading Research Repositories and Databases, including IEEE, Springer and Elsevier, based on Detection Accuracy, Adaptability, Computational Overheads, Resistance to Evasion Techniques, etc. Signature-Based Detection Systems offer a fast Response Time, but do not provide detection of new or Obfuscated Patterns. Conversely, Behaviour-Based Models provide for enhanced Generalization by creating a Model of Legitimate Query Behaviour. The new Machine Learning Measures along with Deep Learning Methods show effective performance for SQL Injection Detection because their Precision Rates reach 95% through their use of Feature-Binding and Neural Representational Learning techniques. The Methods experience multiple problems that stem from Data Imbalance issues and challenges with Interpretability and difficulties in achieving Real-Time Scalability.

Downloads

Download data is not yet available.

Downloads

Published

2026-06-23

How to Cite

Maguluri V Lavanya, & Kranthi Kumar Singamaneni. (2026). DETECTING SQL INJECTION ATTACKS: A SYSTEMATIC SURVEY OF SIGNATURE, BEHAVIOR AND LEARNING-BASED METHODS. International Journal of Computer Information Systems and Industrial Management Applications, 18(1s), 8. https://doi.org/10.70917/ijcisim-2026-2197

Issue

Section

Original Articles