00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

Securing Web Applications Against SQL Injection and XSS Attacks

Authors

Chandrashekhar Moharir

Deputy General Manager HCL America Dallas, Texas, United States (IN)

Shiva Kiran Lingishetty

Senior Solutions Architect Amdocs Alpharetta, Georgia, United States (IN)

Arvind Kamboj

Department of Computer Science & Engineering, Shivalik College of Engineering, Dehradun (IN)

Article Information

DOI: 10.51583/IJLTEMAS.2025.140500025

Subject Category: Cybersecurity

Volume/Issue: 14/5 | Page No: 203-208

Publication Timeline

Submitted: 2025-06-03

Published: 2025-06-03

Abstract

Abstract: This paper presents a comprehensive approach to enhancing web application security by mitigating two of the most prevalent and dangerous threats: SQL Injection (SQLi) and Cross-Site Scripting (XSS) attacks. Traditional defense mechanisms such as Web Application Firewalls (WAFs) and rule-based filtering often fall short due to their static nature and limited adaptability to novel or obfuscated attack vectors. To address these shortcomings, the proposed methodology integrates machine learning-based models trained on diverse datasets to accurately detect and classify malicious inputs. Extensive experiments were conducted in both controlled and real-time environments, evaluating the system’s performance using key metrics including accuracy, precision, recall, and F1 score. The results demonstrate that the machine learning model significantly outperforms traditional methods, achieving a detection accuracy of 96.4%, with high precision and recall values, thus offering both effectiveness and efficiency. The system also exhibits scalability and adaptability, making it suitable for deployment in live web applications. This research highlights the critical role of intelligent, data-driven systems in modern cybersecurity frameworks and establishes a strong foundation for future work focused on developing proactive and resilient web application defenses.

Keywords

SQL Injection, Cross-Site Scripting, Web Application Security, Machine Learning, Attack Detection

Downloads

References

1. Alenezi, M., & Jhanjhi, N. Z. (2021). A machine learning-based web application firewall for detecting SQL injection and cross-site scripting attacks. IEEE Access, 9, 103712–103724. [Google Scholar] [Crossref]

2. Amin, R., Sultana, M., & Islam, M. R. (2020). Detection of cross-site scripting and SQL injection vulnerabilities with machine learning algorithms. International Journal of Information Security Science, 9(3), 45–53. [Google Scholar] [Crossref]

3. Barbhuiya, F. A., & Hazarika, S. M. (2021). A hybrid approach to detect and prevent XSS and SQLi attacks in web applications. International Journal of Information Security, 20, 215–230. [https://doi.org/10.1007/s10207-020-00515-3] (https://doi.org/10.1007/s10207-020-00515-3) [Google Scholar] [Crossref]

4. Bhandari, R., Yadav, R., & Rajpoot, D. S. (2022). Cyber threat detection using supervised machine learning techniques in web applications. Security and Privacy, 5(3), e167. [https://doi.org/10.1002/spy2.167] (https://doi.org/10.1002/spy2.167) [Google Scholar] [Crossref]

5. Chatterjee, S., & Sengupta, S. (2020). Towards preventing XSS attacks using deep learning techniques. Procedia Computer Science, 167, 2404–2413. [https://doi.org/10.1016/j.procs.2020.03.296] (https://doi.org/10.1016/j.procs.2020.03.296) [Google Scholar] [Crossref]

6. Gupta, R., & Chauhan, N. (2023). Lightweight detection model for SQL injection attacks using random forest. Journal of Cybersecurity and Privacy, 3(1), 95–109. [https://doi.org/10.3390/jcp3010007] (https://doi.org/10.3390/jcp3010007) [Google Scholar] [Crossref]

7. Han, W., Wu, Y., & Zhang, C. (2021). Detection of web attacks using attention-based deep neural networks. Computers & Security, 106, 102282. [https://doi.org/10.1016/j.cose.2021.102282] (https://doi.org/10.1016/j.cose.2021.102282) [Google Scholar] [Crossref]

8. Javed, M. A., & Hashem, I. A. T. (2020). Intelligent system for web security: Detecting SQLi and XSS using ensemble learning. IEEE Transactions on Industrial Informatics, 16(11), 7236–7245. [https://doi.org/10.1109/TII.2020.2968912] (https://doi.org/10.1109/TII.2020.2968912) [Google Scholar] [Crossref]

9. Kaur, P., & Arora, A. (2021). A deep learning model to prevent injection attacks in web applications. Cybersecurity, 4(1), 12. [https://doi.org/10.1186/s42400-021-00079-5] (https://doi.org/10.1186/s42400-021-00079-5) [Google Scholar] [Crossref]

10. Kumar, S., & Sharma, A. (2022). An adaptive intrusion detection system using gradient boosting for web-based attacks. Journal of Information Security and Applications, 65, 103082. [https://doi.org/10.1016/j.jisa.2022.103082] (https://doi.org/10.1016/j.jisa.2022.103082) [Google Scholar] [Crossref]

11. Lin, C., Hsu, C. H., & Liu, Y. (2020). Hybrid machine learning technique for detecting SQL injection and XSS vulnerabilities. Future Generation Computer Systems, 113, 370–384. [https://doi.org/10.1016/j.future.2020.07.015] (https://doi.org/10.1016/j.future.2020.07.015) [Google Scholar] [Crossref]

12. Mishra, A., & Dubey, H. (2024). Real-time web threat detection using LSTM-based anomaly detection framework. Applied Intelligence. [https://doi.org/10.1007/s10489-024-05472-x] (https://doi.org/10.1007/s10489-024-05472-x) [Google Scholar] [Crossref]

13. Rani, S., & Kumar, N. (2023). Web vulnerability scanner using hybrid ML techniques to identify SQL and XSS flaws. International Journal of Cyber-Security and Digital Forensics, 12(1), 14–23. [Google Scholar] [Crossref]

14. Singh, R., & Kaur, A. (2022). A novel deep learning model for detecting web vulnerabilities. International Journal of Information Technology, 14, 1021–1029. [https://doi.org/10.1007/s41870-021-00748-5] (https://doi.org/10.1007/s41870-021-00748-5) [Google Scholar] [Crossref]

15. Zhang, Y., Xu, T., & Wang, L. (2021). Detecting web injection attacks using convolutional neural networks. Journal of Network and Computer Applications, 174, 102886. [https://doi.org/10.1016/j.jnca.2020.102886] (https://doi.org/10.1016/j.jnca.2020.102886) [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.