Securing Web Applications Against SQL Injection and XSS Attacks
Authors
Chandrashekhar Moharir
Deputy General Manager HCL America Dallas, Texas, United States (IN)
Shiva Kiran Lingishetty
Senior Solutions Architect Amdocs Alpharetta, Georgia, United States (IN)
Arvind Kamboj
Department of Computer Science & Engineering, Shivalik College of Engineering, Dehradun (IN)
Article Information
DOI: 10.51583/IJLTEMAS.2025.140500025
Subject Category: Cybersecurity
Volume/Issue: 14/5 | Page No: 203-208
Publication Timeline
Submitted: 2025-06-03
Published: 2025-06-03
Abstract
Abstract: This paper presents a comprehensive approach to enhancing web application security by mitigating two of the most prevalent and dangerous threats: SQL Injection (SQLi) and Cross-Site Scripting (XSS) attacks. Traditional defense mechanisms such as Web Application Firewalls (WAFs) and rule-based filtering often fall short due to their static nature and limited adaptability to novel or obfuscated attack vectors. To address these shortcomings, the proposed methodology integrates machine learning-based models trained on diverse datasets to accurately detect and classify malicious inputs. Extensive experiments were conducted in both controlled and real-time environments, evaluating the system’s performance using key metrics including accuracy, precision, recall, and F1 score. The results demonstrate that the machine learning model significantly outperforms traditional methods, achieving a detection accuracy of 96.4%, with high precision and recall values, thus offering both effectiveness and efficiency. The system also exhibits scalability and adaptability, making it suitable for deployment in live web applications. This research highlights the critical role of intelligent, data-driven systems in modern cybersecurity frameworks and establishes a strong foundation for future work focused on developing proactive and resilient web application defenses.
Keywords
SQL Injection, Cross-Site Scripting, Web Application Security, Machine Learning, Attack Detection
Downloads
References
1. Alenezi, M., & Jhanjhi, N. Z. (2021). A machine learning-based web application firewall for detecting SQL injection and cross-site scripting attacks. IEEE Access, 9, 103712–103724. [Google Scholar] [Crossref]
2. Amin, R., Sultana, M., & Islam, M. R. (2020). Detection of cross-site scripting and SQL injection vulnerabilities with machine learning algorithms. International Journal of Information Security Science, 9(3), 45–53. [Google Scholar] [Crossref]
3. Barbhuiya, F. A., & Hazarika, S. M. (2021). A hybrid approach to detect and prevent XSS and SQLi attacks in web applications. International Journal of Information Security, 20, 215–230. [https://doi.org/10.1007/s10207-020-00515-3] (https://doi.org/10.1007/s10207-020-00515-3) [Google Scholar] [Crossref]
4. Bhandari, R., Yadav, R., & Rajpoot, D. S. (2022). Cyber threat detection using supervised machine learning techniques in web applications. Security and Privacy, 5(3), e167. [https://doi.org/10.1002/spy2.167] (https://doi.org/10.1002/spy2.167) [Google Scholar] [Crossref]
5. Chatterjee, S., & Sengupta, S. (2020). Towards preventing XSS attacks using deep learning techniques. Procedia Computer Science, 167, 2404–2413. [https://doi.org/10.1016/j.procs.2020.03.296] (https://doi.org/10.1016/j.procs.2020.03.296) [Google Scholar] [Crossref]
6. Gupta, R., & Chauhan, N. (2023). Lightweight detection model for SQL injection attacks using random forest. Journal of Cybersecurity and Privacy, 3(1), 95–109. [https://doi.org/10.3390/jcp3010007] (https://doi.org/10.3390/jcp3010007) [Google Scholar] [Crossref]
7. Han, W., Wu, Y., & Zhang, C. (2021). Detection of web attacks using attention-based deep neural networks. Computers & Security, 106, 102282. [https://doi.org/10.1016/j.cose.2021.102282] (https://doi.org/10.1016/j.cose.2021.102282) [Google Scholar] [Crossref]
8. Javed, M. A., & Hashem, I. A. T. (2020). Intelligent system for web security: Detecting SQLi and XSS using ensemble learning. IEEE Transactions on Industrial Informatics, 16(11), 7236–7245. [https://doi.org/10.1109/TII.2020.2968912] (https://doi.org/10.1109/TII.2020.2968912) [Google Scholar] [Crossref]
9. Kaur, P., & Arora, A. (2021). A deep learning model to prevent injection attacks in web applications. Cybersecurity, 4(1), 12. [https://doi.org/10.1186/s42400-021-00079-5] (https://doi.org/10.1186/s42400-021-00079-5) [Google Scholar] [Crossref]
10. Kumar, S., & Sharma, A. (2022). An adaptive intrusion detection system using gradient boosting for web-based attacks. Journal of Information Security and Applications, 65, 103082. [https://doi.org/10.1016/j.jisa.2022.103082] (https://doi.org/10.1016/j.jisa.2022.103082) [Google Scholar] [Crossref]
11. Lin, C., Hsu, C. H., & Liu, Y. (2020). Hybrid machine learning technique for detecting SQL injection and XSS vulnerabilities. Future Generation Computer Systems, 113, 370–384. [https://doi.org/10.1016/j.future.2020.07.015] (https://doi.org/10.1016/j.future.2020.07.015) [Google Scholar] [Crossref]
12. Mishra, A., & Dubey, H. (2024). Real-time web threat detection using LSTM-based anomaly detection framework. Applied Intelligence. [https://doi.org/10.1007/s10489-024-05472-x] (https://doi.org/10.1007/s10489-024-05472-x) [Google Scholar] [Crossref]
13. Rani, S., & Kumar, N. (2023). Web vulnerability scanner using hybrid ML techniques to identify SQL and XSS flaws. International Journal of Cyber-Security and Digital Forensics, 12(1), 14–23. [Google Scholar] [Crossref]
14. Singh, R., & Kaur, A. (2022). A novel deep learning model for detecting web vulnerabilities. International Journal of Information Technology, 14, 1021–1029. [https://doi.org/10.1007/s41870-021-00748-5] (https://doi.org/10.1007/s41870-021-00748-5) [Google Scholar] [Crossref]
15. Zhang, Y., Xu, T., & Wang, L. (2021). Detecting web injection attacks using convolutional neural networks. Journal of Network and Computer Applications, 174, 102886. [https://doi.org/10.1016/j.jnca.2020.102886] (https://doi.org/10.1016/j.jnca.2020.102886) [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Wind Turbine Design for Low Wind Speed Applications: Advancing Renewable Energy Systems Through Wind Tunnel Experiments
- Fast Identification for Evidences in Crime Scene with Macroscopic Properties and Portable Techniques
- Evaluating the Impact of Hello Interval Timer on OSPF Performance for Real-Time Applications Using OPNET
- The Algorithmic Fortress: Ai-Powered Cybersecurity and Anti-Fraud in The Future of Fintech
- Accident Detection on Curved Roads Using Infrared Sensors in Hilly Regions A Case of Chadoora Tehsil, Badgam (J&K)