DETECTING SQL INJECTION ATTACKS: A SYSTEMATIC SURVEY OF SIGNATURE, BEHAVIOR AND LEARNING-BASED METHODS
DOI:
https://doi.org/10.70917/ijcisim-2026-2197Keywords:
SQL Injection Detection, Web Application Security, Signature-Based Methods, Behavior Analysis, Machine Learning, Deep Learning, Hybrid Frameworks, Intrusion Detection, Cybersecurity, Threat MitigationAbstract
SQL Injection (SQLi) is classified as a high priority security vulnerability that affects dynamic web applications and Database-Driven Systems (DBDS). Despite a marked improvement in Defensive Programming and Automated Testing, attackers have continued to find ways to exploit logical errors in Query Construction to gain unauthorized access to DBDS and to manipulate Data. This paper presents a Systematic Review of SQL Injection Detection Techniques, which are categorized using three (3) different approaches - Signature-Based, Behaviour-Based and Learning-Based. This Review identifies and compares all the articles published between 2013 and 202035 in the leading Research Repositories and Databases, including IEEE, Springer and Elsevier, based on Detection Accuracy, Adaptability, Computational Overheads, Resistance to Evasion Techniques, etc. Signature-Based Detection Systems offer a fast Response Time, but do not provide detection of new or Obfuscated Patterns. Conversely, Behaviour-Based Models provide for enhanced Generalization by creating a Model of Legitimate Query Behaviour. The new Machine Learning Measures along with Deep Learning Methods show effective performance for SQL Injection Detection because their Precision Rates reach 95% through their use of Feature-Binding and Neural Representational Learning techniques. The Methods experience multiple problems that stem from Data Imbalance issues and challenges with Interpretability and difficulties in achieving Real-Time Scalability.