• Home
  • Search
  • Improving Malicious Web Code Classification with Sequence by Machine Learning
  • Cite Icon1
  • https://doi.org/10.5573/ieiespc.2014.3.5.319Copy DOI Icon

Improving Malicious Web Code Classification with Sequence by Machine Learning

  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Web applications make life more convenient. Many web applications have several kinds of user input (e.g. personal information, a user"s comment of commercial goods, etc.) for the activities. On the other hand, there are a range of vulnerabilities in the input functions of Web applications. Malicious actions can be attempted using the free accessibility of many web applications. Attacks by the exploitation of these input vulnerabilities can be achieved by injecting malicious web code; it enables one to perform a variety of illegal actions, such as SQL Injection Attacks (SQLIAs) and Cross Site Scripting (XSS). These actions come down to theft, replacing personal information, or phishing. The existing solutions use a parser for the code, are limited to fixed and very small patterns, and are difficult to adapt to variations. A machine learning method can give leverage to cover a far broader range of malicious web code and is easy to adapt to variations and changes. Therefore, this paper suggests the adaptable classification of malicious web code by machine learning approaches for detecting the exploitation user inputs. The approach usually identifies the “looks-like malicious” code for real malicious code. More detailed classification using sequence information is also introduced. The precision for the “looks-like malicious code” is 99% and for the precise classification with sequence is 90%.

Similar Papers
  • Conference Article
  • Citations1

Malicious Code Detection Based on Software Fingerprint

  • Jan 01, 2013
  • Zhimin Yin +2
  • Conference Article

Research on XSS malicious code detection method based on LSTM-LLM cascade architecture

  • Mar 19, 2026
  • Cheng Wei +3
  • Research Article
  • Citations10

Outlier-aware cooperative spectrum sensing in cognitive radio networks

  • Sep 09, 2015
  • Physical Communication
  • Gaurav Kapoor +1
  • Book Chapter
  • Citations1

Vulnerability Detection and Sanitization Synthesis

  • Jan 01, 2017
  • Tevfik Bultan +3
  • Research Article

Design of Malicious Code Detection System Based on Binary Code Slicing

  • Jun 01, 2022
  • 電腦學刊
  • Mohan Liu Mohan Liu +2
  • Conference Article
  • Citations19

Reducing attack surface corresponding to Type 1 cross-site scripting attacks using secure development life cycle practices

  • Feb 01, 2018
  • Syed Nisar Bukhari +2
  • Book Chapter
  • Citations7

Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application

  • Jan 01, 2015
  • Nor Fatimah Awang +1
  • Research Article
  • Citations35

A Malicious Mining Code Detection Method Based on Multi-Features Fusion

  • Sep 01, 2023
  • IEEE Transactions on Network Science and Engineering
  • Shudong Li +5
  • Conference Article
  • Citations102

Security in multi-tenancy cloud

  • Oct 01, 2010
  • Amarnath Jasti +3
  • Conference Article
  • Citations48

Detecting SQL Injection Attacks in Cloud SaaS using Machine Learning

  • May 01, 2020
  • Dharitri Tripathy +2
  • Conference Article
  • Citations3

Web application reconnaissance scan detection using LSTM network based deep learning

  • Mar 10, 2022
  • Bronjon Gogoi +2
  • Conference Article
  • Citations5

Web application database protection from SQLIA using permutation encoding

  • Mar 17, 2021
  • Mohammed Abdulridha Hussain +6
  • Conference Article
  • Citations6

An approach to minimize false positive in SQLI vulnerabilities detection techniques through data mining

  • Jul 01, 2014
  • Mukesh Kumar Gupta +2
  • Conference Article
  • Citations61

Intrusion recovery for database-backed web applications

  • Oct 23, 2011
  • Ramesh Chandra +4
  • Conference Article
  • Citations5

A security analysis tool for web application reinforcement against SQL injection attacks (SQLIAs)

  • Aug 01, 2013
  • Z Lashkaripour +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.