SQL (Structured Query Language) injection detection method and system based on grammar and semantic feature fusion network and storage medium
By adopting a detection method based on syntax semantic feature fusion network in SQL injection attack detection, using BERT and ChatGPT to extract and fuse syntax semantic features, the problem of insufficient detection capabilities in the face of complex and advanced SQL injection attacks is solved, and a more efficient and accurate detection effect is achieved.
Patent Information
- Application Number
- CN202510210417.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-13
AI Technical Summary
When facing complex and changing advanced SQL injection attacks, traditional SQL injection attack detection methods lack detection capabilities and flexibility, resulting in high missed alarms and false alarm warnings.
The detection method based on the syntax semantic feature fusion network is adopted to extract the semantic features of SQL statements through the BERT model, and the prompt engineering is automatically extracted with ChatGPT, and the cross-attention mechanism is used to weight and fusion the syntax features to form a detection model.
It significantly improves the accuracy and efficiency of SQL injection attack detection, and can effectively identify complex and changeable advanced SQL injection attacks, reducing the rate of missed reports and false alarms.
Smart Images

Figure CN120150993A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network information security, and more specifically to a SQL injection detection method, system and storage medium based on a grammatical and semantic feature fusion network. Background Art
[0002] With the rapid development of Internet of Things technology, the deep integration of technologies such as smart devices, sensor networks and cloud computing has brought unprecedented convenience to enterprises, institutions and individuals, but it has also caused the number and complexity of network threats to rise sharply. Hackers not only use traditional technical means, but also use advanced artificial intelligence tools such as ChatGPT to generate highly adversarial SQL injection attack threats at a lower cost and higher efficiency. These threats have a strong ability to bypass traditional security protection equipment. At present, the methods used to detect SQL injection mainly include regular rules based on manual formulation, grammatical semantic analysis, and threat intelligence matching. However, these methods seem to be stretched in the face of increasingly advanced network security threats.
[0003] Existing SQL injection detection methods mainly rely on fixed rule bases, which makes them incapable of dealing with ever-changing and evolving attack patterns, especially those that use complex obfuscation techniques or new attack vectors. Traditional methods are often unable to effectively identify highly concealed, multi-layered encoded, protocol anomalies and other combined attack methods due to their static characteristics, resulting in a high rate of missed detections. In addition, the limitations of traditional technologies also lead to a large number of false positive warnings, making it difficult for security personnel to quickly and accurately screen out real threats and conduct effective attack tracing in a large number of alarms.
[0004] There is currently no ideal solution to the above problems. There is an urgent need for a new detection method that can effectively deal with complex and changeable SQL injection attacks to improve the accuracy and efficiency of detection and ensure data security and system stability in the Internet of Things environment. Summary of the invention
[0005] In view of this, the present invention provides a SQL injection detection method, system and storage medium based on a grammatical and semantic feature fusion network, so as to at least solve the technical problem that traditional SQL injection attack detection methods have obvious insufficient detection capabilities and flexibility for complex and changeable advanced SQL injection attacks (especially attacks using highly adversarial means such as obfuscation, encoding and protocol anomalies).
[0006] In order to achieve the above object, the present invention adopts the following technical solution:
[0007] A SQL injection detection method based on a grammatical and semantic feature fusion network includes the following steps:
[0008] Collect multiple SQL injection samples as training data and preprocess them;
[0009] Use the preprocessed training data to train a detection model. The detection model uses the BERT model to extract semantic features of SQL statements in the training data, automatically extracts syntactic features with the help of ChatGPT through prompt engineering, and uses a cross-attention mechanism to perform weighted fusion on the syntactic features;
[0010] Receive traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect SQL injection attacks in the traffic data to be detected.
[0011] Optionally, the detection model uses the BERT model to extract semantic features of SQL statements, specifically including the following steps:
[0012] Obtain vector embeddings with context information from the training data. The BERT model combines token embeddings, segment embeddings, and position embeddings to capture the semantic meaning of each token, its role in the sentence, and its position in the sequence; add the token embeddings, segment embeddings, and position embeddings to form the final input representation of each token and input it into the encoder layer for further processing; each encoder layer contains a self-attention mechanism and a feed-forward neural network, and the output of the self-attention mechanism undergoes a linear transformation to obtain the final output; extract the vector representation of the tokens from the output of the encoder layer to generate feature vectors.
[0013] Optionally, obtaining vector embeddings with context information from the training data is specifically: tokenize the training data, add [CLS] tokens and [SEP] tokens at the beginning and end of the tokenized sequence respectively; use token embeddings to convert each token into a vector representation of a fixed dimension; segment embeddings are used to distinguish between two sentences in a sentence pair task, and the same sentence shares the same segment embedding, and position embeddings are used to encode the position information of the tokens within the sequence, thereby preserving the order of the input sequence, and each position has a fixed vector representation retrieved by looking up the embedding matrix.
[0014] Optionally, automatically extract syntactic features with the help of ChatGPT through prompt engineering, and use a cross-attention mechanism to perform weighted fusion on the syntactic features, specifically: use the semantic feature vector of the BERT extraction model as the query, the syntactic feature vector extracted by ChatGPT as the key and value, generate a representation that fuses the information of the two sequences by calculating the attention scores and weighting the representation of the latter sequence, and use it as the input to the classifier.
[0015] Optionally, the traffic data to be detected is input into a trained detection model for processing. Specifically, the traffic data to be detected is vectorized to obtain the vectorized traffic data to be detected. The trained detection model is used to detect the vectorized traffic data to be detected. If the vectorized traffic data to be detected contains an SQL attack statement, it is determined that there is an SQL injection attack in the traffic data to be detected.
[0016] Optionally, preprocess the training data. Specifically, clean the text of invisible characters, consecutive repeated characters, special characters, and redundant spaces, and unify the message format. Split the consecutive text in the training data into independent words or phrases. Sort the high-frequency words in the training data and filter out the stop words.
[0017] Optionally, conduct threat analysis, attack purpose qualification, attack payload research, attack method research, attack result analysis, and countermeasure generation for the detected SQL injection attack.
[0018] An SQL injection detection system based on a syntax-semantic feature fusion network includes:
[0019] A training data acquisition module: used to collect multiple SQL injection samples as training data and preprocess them;
[0020] A detection model training module: used to train a detection model using the preprocessed training data. The detection model uses the BERT model to extract the semantic features of the SQL statements in the training data, automatically extracts the syntax features with the help of ChatGPT through prompt engineering, and uses a cross-attention mechanism to weight and fuse the syntax features;
[0021] An attack detection module: used to receive the traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect the SQL injection attack in the traffic data to be detected.
[0022] A computer storage medium stores a computer program thereon. When the computer program is executed by a processor, the steps of any one of the SQL injection detection methods based on a syntax-semantic feature fusion network are implemented.
[0023] As can be seen from the above technical solutions, compared with the prior art, the present invention provides a method, system and storage medium for SQL injection detection based on a grammar-semantic feature fusion network. When receiving traffic data to be detected, these data can be input into a trained detection model for processing to achieve efficient detection of SQL injection attacks, thereby solving the technical problem that traditional SQL injection attack detection methods have obvious deficiencies in detection ability and flexibility for complex and changeable advanced SQL injection attacks (especially attacks using highly adversarial means such as obfuscation, encoding, and protocol anomalies), and achieving the technical effect of significantly improving the accuracy and efficiency of SQL injection attack detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided accompanying drawings.
[0025] Figure 1 Schematic diagram of the overall structure of the detection model of the present invention;
[0026] Figure 2 Schematic diagram of the embedding layer of the present invention;
[0027] Figure 3 Schematic diagram of the prompt engineering design of the present invention;
[0028] Figure 4 Schematic diagram of the confusion matrix of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0030] An embodiment of the present invention discloses a method for SQL injection detection based on a grammar-semantic feature fusion network, including the following steps:
[0031] Step 1: Collect multiple SQL injection samples as training data and perform preprocessing;
[0032] Step 2: Use the preprocessed training data to train the detection model. The detection model uses the BERT model to extract the semantic features of the SQL statements in the training data, automatically extracts the syntactic features with the help of ChatGPT through prompt engineering, and uses the cross-attention mechanism to perform weighted fusion on the syntactic features;
[0033] Step 3: Receive the traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect SQL injection attacks in the traffic data to be detected.
[0034] Further, in Step 1, clean the invisible characters, consecutive repeated characters, special characters, and extra spaces in the SQL injection samples, and unify the message format; split the consecutive text in the SQL injection samples into independent words or phrases; sort the high-frequency words in the SQL injection samples and filter out the stop words; where the stop words are words that appear frequently in the text but contribute little to text analysis.
[0035] Further, in Step 2, the detection model uses the BERT model to extract the semantic features of the SQL statements, specifically including the following steps:
[0036] Obtain vector embeddings with context information from the training data. The BERT model combines token embeddings, segment embeddings, and position embeddings to capture the semantic meaning of each token, its role in the sentence, and its position in the sequence; add the token embeddings, segment embeddings, and position embeddings to form the final input representation of each token, and input it into the encoder layer for further processing; each encoder layer contains a self-attention mechanism and a feed-forward neural network, and the output of the self-attention mechanism undergoes a linear transformation to obtain the final output; extract the vector representation of the tokens from the output of the encoder layer to generate feature vectors.
[0037] Even further, obtain vector embeddings with context information from the original text representation. As Figure 2 shown, the embedding layer of the BERT model consists of three parts: Token embedding, Segment embedding, and Position embedding. Before embedding, BERT first tokenizes the original text, and then adds a special [CLS] token at the beginning and an additional [SEP] token at the end of the tokenized sequence. Subsequently, use the token embedding to convert each token into a vector representation of a fixed dimension. This can be mathematically expressed as TokenEmbedding(t i ) = E[t i , where E is the embedding matrix, and t i represents the i-th token. Segment embedding is used to distinguish between two sentences in a sentence pair task. As Figure 2As shown in , when all tokens belong to the same sentence, they share the same segment ID. Position embedding is used to encode the position information of the token within the sequence, thereby preserving the order of the input sequence. Each position has a fixed vector representation, which is retrieved by looking up the embedding matrix. Specifically, this can be expressed as PositionEmbedding(p i )=P[p i ], where P represents the position embedding matrix, p i represents the i-th position. By combining token embeddings, segment embeddings, and position embeddings, BERT can capture the semantic meaning of each token, its role in the sentence (through segment embeddings), and its position in the sequence (through position embeddings). These embeddings are then added together to form the final input representation of each token and fed into the Transformer encoder layer for further processing.
[0038] The input embedding vector passes through 12 BERT encoder layers, each of which contains a self-attention mechanism and a feedforward neural network. After passing through the embedding layer, we get the embedding vector X. The embedding vector X undergoes three linear transformations to get the query matrix Q = XW Q , key matrix K = XW K Sum matrix V = XW V , where W Q , W K and W V is a learnable weight matrix. Then, the self-attention score is calculated using formula (1), where d k is the dimension of the key vector:
[0039]
[0040] In order to capture different attention patterns, BERT uses a multi-head self-attention mechanism. The matrices Q, K, and V are divided into multiple h heads, and the attention of each head is calculated independently. The results are then concatenated and transformed linearly:
[0041] MultiHead(Q,K,V)=Concat(head 1 ,head 2 ,...,head h )W 0 (2)
[0042] The output of the multi-head self-attention mechanism is linearly transformed to obtain the final output
[0043] Out, expressed as:
[0044] Output=MultiHead(Q,K,V)W 0 (3).
[0046] Extract the vector representation of the [CLS] token from the output of the final encoder layer, thereby generating a 768-dimensional feature vector.
[0047] As Figure 3 shown, in the present invention, 768-dimensional syntactic feature vectors are extracted using BERT, and 768-dimensional semantic feature vectors are extracted using GPT. Subsequently, as Figure 4 shown, we use these syntactic feature vectors as Q (queries), and semantic feature vectors as K (keys) and V (values) in the cross-attention mechanism to facilitate feature fusion. Finally, the fused multi-modal features are used as the input to the classifier for classification.
[0048] Input the traffic data to be detected into the trained detection model for processing. Specifically: vectorize the traffic data to be detected to obtain the vectorized traffic data to be detected; use the trained detection model to detect the vectorized traffic data to be detected. If the vectorized traffic data to be detected contains SQL attack statements, it is determined that the traffic data to be detected has a SQL injection attack.
[0049] Further, in step 1 of this embodiment, preprocess the training data. Specifically: perform text cleaning on invisible characters, consecutive repeated characters, special characters, and extra spaces, and unify the message format; split the consecutive text in the training data into independent words or phrases; sort the high-frequency words in the training data and filter out the stop words.
[0050] Further, in this embodiment, perform threat analysis, attack purpose qualitative analysis, attack payload research and judgment, attack method research and judgment, attack result analysis, and countermeasure generation on the detected SQL injection attack.
[0051] This embodiment solves the problem of insufficient detection ability of traditional SQL injection attack detection methods for new and complex SQL injection attacks, and significantly improves the accuracy and efficiency of SQL injection attack detection.
[0052] This embodiment also discloses a SQL injection detection system based on a syntax-semantic feature fusion network, including:
[0053] A training data acquisition module: used to collect multiple SQL injection samples as training data and preprocess them;
[0054] Detection model training module: It is used to train the detection model by using the preprocessed training data. The detection model uses the BERT model to extract the semantic features of the SQL statements in the training data, automatically extracts the syntactic features with the help of ChatGPT through prompt engineering, and uses the cross-attention mechanism to perform weighted fusion on the syntactic features;
[0055] Attack detection module: It is used to receive the traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect SQL injection attacks in the traffic data to be detected.
[0056] This embodiment also discloses a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the SQL injection detection methods based on the syntax-semantic feature fusion network are realized.
[0057] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, please refer to the description of the method part.
[0058] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A SQL injection detection method based on a syntactic and semantic feature fusion network, characterized in that: The following steps are involved: Collect multiple SQL injection samples as training data and preprocess them; The detection model is trained using the preprocessed training data. The detection model uses the BERT model to extract the semantic features of the SQL statements of the training data, and automatically extracts the grammatical features with the help of ChatGPT through prompt engineering, and uses the cross-attention mechanism to perform weighted fusion on the grammatical features; Receive the traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect the SQL injection attack in the traffic data to be detected.
2. According to claim 1, a SQL injection detection method based on a grammatical and semantic feature fusion network is characterized in that: The detection model uses the BERT model to extract the semantic features of SQL statements, specifically including the following steps: To obtain vector embeddings with contextual information from the training data, the BERT model combines tag embeddings, segment embeddings, and position embeddings to capture the semantic meaning of each tag, its role in the sentence, and its position in the sequence; the tag embeddings, segment embeddings, and position embeddings are added together to form the final input representation of each tag, and input to the encoder layer for further processing; each encoder layer contains a self-attention mechanism and a feedforward neural network, and the output of the self-attention mechanism is linearly transformed to obtain the final output; the vector representation of the tag is extracted from the output of the encoder layer to generate a feature vector.
3. The SQL injection detection method based on grammatical and semantic feature fusion network according to claim 2 is characterized in that: Vector embedding with contextual information is obtained from the training data. Specifically, the training data is labeled by adding [CLS] and [SEP] tags at the beginning and end of the tokenized sequence respectively; each tag is converted into a vector representation of fixed dimension using tag embedding; segment embedding is used to distinguish two sentences in the sentence pair task, and the same sentence enjoys the same segment embedding. Position embedding is used to encode the position information of the tag within the sequence, thereby preserving the order of the input sequence. Each position has a fixed vector representation, which is retrieved by looking up the embedding matrix.
4. The SQL injection detection method based on grammatical and semantic feature fusion network according to claim 1 is characterized in that: The prompt engineering uses ChatGPT to automatically extract grammatical features, and uses a cross-attention mechanism to weightedly fuse the grammatical features. Specifically, the semantic feature vector of the BERT extraction model is used as the query, and the grammatical feature vector extracted by ChatGPT is used as the key and value. By calculating the attention score and weighting the representation of the latter sequence, a representation that fuses the information of the two sequences is generated as the input of the classifier.
5. The SQL injection detection method based on grammatical and semantic feature fusion network according to claim 1 is characterized in that: The traffic data to be detected is input into the trained detection model for processing, specifically: the traffic data to be detected is vectorized to obtain the vectorized traffic data to be detected; the vectorized traffic data to be detected is detected using the trained detection model, and if the vectorized traffic data to be detected contains SQL attack statements, it is determined that the traffic data to be detected has an SQL injection attack.
6. The SQL injection detection method based on grammatical and semantic feature fusion network according to claim 1 is characterized in that: Preprocess the training data, specifically: clean invisible characters, consecutive repeated characters, special characters and extra spaces, and unify the message format; split the continuous text in the training data into independent words or phrases; sort the high-frequency words in the training data and filter out stop words.
7. The SQL injection detection method based on grammatical and semantic feature fusion network according to claim 1 is characterized in that: Conduct threat analysis on detected SQL injection attacks, characterize attack objectives, determine attack payloads, determine attack methods, analyze attack results, and generate countermeasures.
8. A SQL injection detection system based on a syntactic and semantic feature fusion network, characterized in that: include: Training data acquisition module: used to collect multiple SQL injection samples as training data and pre-process them; Detection model training module: used to train the detection model using the preprocessed training data. The detection model uses the BERT model to extract the semantic features of the SQL statements of the training data, and automatically extracts the grammatical features with the help of ChatGPT through the prompt engineering, and uses the cross-attention mechanism to perform weighted fusion on the grammatical features; Attack detection module: used to receive the traffic data to be detected, input the traffic data to be detected into the trained detection model for processing, and detect SQL injection attacks in the traffic data to be detected.
9. A computer storage medium, characterized in that The computer storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the SQL injection detection method based on the grammatical and semantic feature fusion network as described in any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Multi-sample attack detection and defense method oriented to large language model
CN120542579A
Cross-network data security exchange method
CN120856627A
Cross-network data security exchange system
CN120880736A