<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">40121</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2023.040121</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Injections Attacks Efficient and Secure Techniques Based on Bidirectional Long Short Time Memory Model</article-title>
<alt-title alt-title-type="left-running-head">Injections Attacks Efficient and Secure Techniques Based on Bidirectional Long Short Time Memory Model</alt-title>
<alt-title alt-title-type="right-running-head">Injections Attacks Efficient and Secure Techniques Based on Bidirectional Long Short Time Memory Model</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Farea</surname><given-names>Abdulgbar A. R.</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Amran</surname><given-names>Gehad Abdullah</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><email>jehad.westran@gmail.com</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Farea</surname><given-names>Ebraheem</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Alabrah</surname><given-names>Amerah</given-names></name><xref ref-type="aff" rid="aff-4">4</xref><email>aalobrah@ksu.edu.sa</email></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Abdulraheem</surname><given-names>Ahmed A.</given-names></name><xref ref-type="aff" rid="aff-5">5</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Mursil</surname><given-names>Muhammad</given-names></name><xref ref-type="aff" rid="aff-6">6</xref></contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western"><surname>Al-qaness</surname><given-names>Mohammed A. A.</given-names></name><xref ref-type="aff" rid="aff-7">7</xref></contrib>
<aff id="aff-1"><label>1</label><institution>School of Big Data &#x0026; Software Engineering, Chongqing University</institution>, <addr-line>Chongqing, 401331</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Management Science Engineering, Dalian University of Technology</institution>, <addr-line>Dalian, 116024</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>Software College, Northeastern University</institution>, <addr-line>Shenyang, 110169</addr-line>, <country>China</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Information Systems, College of Computer and Information Science, King Saud University</institution>, <addr-line>Riyadh, 11543</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-5"><label>5</label><institution>Department of Management Science and Engineering, South China University of Technology</institution>, <addr-line>Guangzhou, 510641</addr-line>, <country>China</country></aff>
<aff id="aff-6"><label>6</label><institution>Department of Computer Engineering and Mathematics, University of Rovira i Virgili</institution>, <addr-line>Tarragona</addr-line>, <country>Spain</country></aff>
<aff id="aff-7"><label>7</label><institution>College of Physics and Electronic Information Engineering, Zhejiang Normal University</institution>, <addr-line>Jinhua, 321004</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Authors: Gehad Abdullah Amran. Email: <email>jehad.westran@gmail.com</email>; Amerah Alabrah. Email: <email>aalobrah@ksu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2023</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>08</day><month>10</month><year>2023</year></pub-date>
<volume>76</volume>
<issue>3</issue>
<fpage>3605</fpage>
<lpage>3622</lpage>
<history>
<date date-type="received"><day>06</day><month>3</month><year>2023</year></date>
<date date-type="accepted"><day>13</day><month>6</month><year>2023</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Farea et al.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Farea et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_40121.pdf"></self-uri>
<abstract>
<p>E-commerce, online ticketing, online banking, and other web-based applications that handle sensitive data, such as passwords, payment information, and financial information, are widely used. Various web developers may have varying levels of understanding when it comes to securing an online application. Structured Query language SQL injection and cross-site scripting are the two vulnerabilities defined by the Open Web Application Security Project (OWASP) for its 2017 Top Ten List Cross Site Scripting (XSS). An attacker can exploit these two flaws and launch malicious web-based actions as a result of these flaws. Many published articles focused on these attacks&#x2019; binary classification. This article described a novel deep-learning approach for detecting SQL injection and XSS attacks. The datasets for SQL injection and XSS payloads are combined into a single dataset. The dataset is labeled manually into three labels, each representing a kind of attack. This work implements some pre-processing algorithms, including Porter stemming, one-hot encoding, and the word-embedding method to convert a word&#x2019;s text into a vector. Our model used bidirectional long short-term memory (BiLSTM) to extract features automatically, train, and test the payload dataset. The payloads were classified into three types by BiLSTM: XSS, SQL injection attacks, and normal. The outcomes demonstrated excellent performance in classifying payloads into XSS attacks, injection attacks, and non-malicious payloads. BiLSTM&#x2019;s high performance was demonstrated by its accuracy of 99.26&#x0025;.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Web security</kwd>
<kwd>SQL injection</kwd>
<kwd>XSS</kwd>
<kwd>deep learning</kwd>
<kwd>RNN</kwd>
<kwd>LSTM</kwd>
<kwd>BiLSTM</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>King Saud University, Riyadh, Saudi Arabia</funding-source>
<award-id>RSP2023R476</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>In recent years, the demand for web applications has rapidly increased. Using the web may significantly reduce enterprises&#x2019; distribution costs for information, products, and services [<xref ref-type="bibr" rid="ref-1">1</xref>]. Vulnerability trends show that applications have a large number of vulnerabilities. In addition, SQL injection and cross-site scripting have been widely documented application vulnerabilities. SQL injections are more dangerous attacks because they can affect vital databases for any company. The exposure must be repaired at the code level, while the developer or programmer must take remedial action from a response perspective [<xref ref-type="bibr" rid="ref-2">2</xref>]. As long as web applications are not very secure, several well-designed injections and malicious scripts can be performed on the database and the victim browser. Intruders may exploit this situation and do malicious actions such as malware distribution, cookie theft, and session hijacking to steal users&#x2019; credentials. This sensitive data could be transferred to any third party, including a hacker&#x2019;s or intruder&#x2019;s server [<xref ref-type="bibr" rid="ref-3">3</xref>].</p>
<p>A SQL injection attack is a type of attack that targets web applications and any applications dealing with the database. The attacker can exploit the weakness of user input filtering and inject illegal SQL queries or malicious payloads, which execute on the database as a legal query. SQL Injection Attacks can destroy the target web application&#x2019;s confidentiality, integrity, and availability. The attacker can gain any sensitive information from the database or even destroy the database [<xref ref-type="bibr" rid="ref-4">4</xref>]. On the other hand, Web applications can be vulnerable to Cross-Site Scripting (XSS) attacks, in which an attacker takes control of a user&#x2019;s browser and executes malicious Hyper Text Markup Language (HTML)/JavaScript code in order to steal the user&#x2019;s credentials. This can be done in a number of ways, like the theft of cookies, the hijacking of a user&#x2019;s session, the distribution of malware, or a redirect to a malicious page [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>According to the similarities between the way of working of these two attacks, which lead us to work on these two attacks. Both SQL injection and XSS are code injection attacks that use the same mechanism to attack the website [<xref ref-type="bibr" rid="ref-6">6</xref>]. The intruder can inject SQL or XSS payloads on website user inputs or Uniform Resource Locators (URLs). The intruder can perform malicious actions on the database, damaging the attacked data or even stealing website cookies. SQL injection and XSS attacks can be used to serve these purposes. A web application consists of server-side, client-side, and database servers. An XSS attack is a malicious script executed on the client browser, whereas an SQL injection attack is a malicious SQL query executed on the database server. According to OWASP (Open Web Application Security Project), SQL injection and cross-site scripting (XSS) are ranked in OWASP&#x2019;s top ten 2017 web application security risks and vulnerabilities [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
<p>Many articles have been published in the area of web application attacks as well as in the field of web application security. However, most studies still have drawbacks and weak points, such as performing multiclassification attacks, which can specify the types of detected attacks and the correct classification rate. Some current work uses binary classification (normal and malicious payloads), which deals with all types of attacks as a single attack without any differentiation between them [<xref ref-type="bibr" rid="ref-8">8</xref>&#x2013;<xref ref-type="bibr" rid="ref-11">11</xref>]. It is worth mentioning that some research focused only on XSS [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>], and other studies focused only on SQL injection attacks [<xref ref-type="bibr" rid="ref-9">9</xref>]. The most relevant work is by Abaimov et al. [<xref ref-type="bibr" rid="ref-6">6</xref>], who built (CODDLE) a convolutional deep neural network model to detect SQL injection and XSS attacks, but he used a separate dataset for each attack and obtained less than our results.</p>
<p>Our key contributions to this research are as follows:
<list list-type="bullet">
<list-item><p>We propose a new methodology based on the BiLSTM recurrent neural network for detecting and multi-classify SQL injection and XSS attacks.</p></list-item>
<list-item><p>The proposed model utilized textual data containing SQL injection and XSS payloads to classify them into three classes, which are XSS, SQL injection, and normal payloads. To achieve high performance in detection, the model utilized Recurrent Neural Networks (RNNs), which consider the sequence of sentences or texts, resulting in excellent results in all evaluation metrics, including accuracy, precision, recall, and F1 score.</p></list-item>
</list></p>
<p>Following the structure of the paper, the rest of the work is organized as follows: <xref ref-type="sec" rid="s2">Section 2</xref> presents relevant studies that connect anomaly detection techniques for web application attacks with deep learning. <xref ref-type="sec" rid="s3">Section 3</xref> introduces the methodology of the proposed model. Model implementation and experimental setup are explained in detail in <xref ref-type="sec" rid="s4">Section 4</xref>. <xref ref-type="sec" rid="s5">Section 5</xref> shows the results of the proposed model with further details and discussion. In <xref ref-type="sec" rid="s6">Section 6</xref>, the conclusions are summed up, and ideas for further studies are suggested.</p>
</sec>
<sec id="s2"><label>2</label><title>Related Works</title>
<p>Recently much work has been carried out for the discrimination of different kinds of Cross-Site Scripting (XSS) and SQL injection attacks [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>].</p>
<sec id="s2_1"><label>2.1</label><title>SQL Injection</title>
<p>Xie et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] described in their study entitled Elastic-Pooling, conventional neural network (CNN)-based (EP-CNN), a deep learning model used for detecting SQL injection attacks in web applications based on weblogs. EP-CNN model Used the Word2vec method to convert the original query to a vector. Then, an elastic pooling layer is added to three layers of convolution kernels after the convolution layers. Padding in convolution must be employed to keep the input and output dimensions equal when using several convolution layers of different sizes. The outside of this layer passed on other convolution kernel layers without trimming the data. This model achieved an accuracy of 98.7&#x0025; on the test set. Chen et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] proposed using word embedding and CNN Multilayer Perceptron (MLP) algorithms to prevent SQL injection attacks as a novel approach. The HTTP requests are denoised and decoded, then Word2Vec produces word embeddings of these decoded characters, trains an MLP, CNN model, and then utilizes the classifier to identify fraudulent requests. Both models successfully detect SQL injection attacks. MLP is 98.5&#x0025; accurate, whereas CNN is 98.2&#x0025; accurate. In their study, Hasan et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] created a heuristic algorithm based on machine learning that was trained on a limited amount of data. They also developed a Graphical User Interface (GUI) application for five models. The Ensemble Boosted Trees model had the most accurate results, with an accuracy rate of 93.8&#x0025;. However, the researchers suggest adding more infected statements to the dataset to improve the algorithm&#x2019;s accuracy. Abdalla et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] aimed to prevent SQL Injection Attacks (SQLIA) with an adaptive model that relies on runtime validation to detect such attacks. However, the model&#x2019;s accuracy was restricted to 86.6&#x0025;, and no machine-learning mechanisms were implemented. The investigation used a dataset containing 4201 entries.</p>
</sec>
<sec id="s2_2"><label>2.2</label><title>Cross-Site Scripting (XSS)</title>
<p>In 2018, DeepXSS [<xref ref-type="bibr" rid="ref-8">8</xref>] used the RNN LSTM algorithm and the Word2vec technique to detect XSS attacks. The proposed method maps each XSS payload to a feature vector using the Word2vec CBOW model. The LSTM technique is then used to train and test XSS payload datasets. The DeepXSS model performed well, with an F1 score accuracy of 98.7&#x0025;, precision of 99.57&#x0025;, and recall of 97.9&#x0025;. DeepXSS can be enhanced to detect more web app attacks. Sharma et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] emphasized the importance of feature set extraction in detecting web-based attacks. They propose an approach to extract feature sets that can significantly improve results when used with a machine learning-based intrusion detection model. The authors conducted an experiment using the CSIC HTTP 2010 dataset and the Weka tool, which involved three steps. Firstly, the data was pre-processed with a python script. Secondly, features were extracted from the dataset based on specific keywords before being fed into Weka for data modeling. Lastly, the data was fed into three Machine learnings (ML) models, J48, OneR, and Na&#x00EF;ve Bayes, in Weka, with J48 producing the best results compared to other classifiers. These findings have implications for developing effective intrusion detection systems for web-based attacks. Kaur et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] developed a machine-learning model to detect malicious attack vectors before a victim&#x2019;s browser processes them. To identify blind XSS and stored XSS attacks, they utilized the Linear Support Vector classification algorithm. The authors gathered features by examining attackers&#x2019; JavaScript events and scripts on the website. The experiment was carried out on Mutillidae, a free website that is vulnerable to attacks, using a linearly separable dataset. The model achieved a high detection accuracy rate of 95.4&#x0025;, with a recall value of 0.951 and a false positive rate of 0.111.</p>
</sec>
<sec id="s2_3"><label>2.3</label><title>SQL Injection and XSS Attacks</title>
<p>In 2017, Liang et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a novel deep learning approach for detecting unusual requests by entailing the unsupervised training of two RNNs. With a sophisticated recurrent unit (Gated Recurrent Unit (GRU) or LSTM unit) for learning the typical request patterns utilizing only typical requests, followed by supervised learning of a neural network classifier that uses the outcome of RNNs as input to differentiate between abnormal and legal requests. The model used normal requests to familiarize the RNNs (LSTM and GRU) with legitimate request patterns. The first RNN looks at URL path structure, while the second looks at query parameter structure. In the final step, an MLP model was trained on the output of prior models to distinguish between normal and abnormal URL occurrence probability sequences. The models&#x2019; accuracy on the CSIC dataset is 97.8&#x0025; for GRU and 98.4&#x0025; for LSTM. GRU and LSTM models achieve 98.5 percent accuracy on the WAF logs dataset. This URL attack classification model did not classify each URL assault according to type. In their study, Tang et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] analyzed the textual content of URLs and developed eight distinctive features. Furthermore, they employed the Payloads dataset and utilized ASCII code to map character sequences into a numerical matrix. The dataset was subsequently trained and tested using LSTM and MLP models with appropriate hyperparameters. Results indicated an accuracy of 99.67&#x0025; and 97.68&#x0025; for LSTM and MLP, respectively. Zhang et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] proposed a method called Adversarial Perturbation for Model Stealing Attack (APMSA) to protect Deep Learning models deployed in the cloud from being stolen by attackers. The method adds noise to the input queries to hide the internal information of the model and prevent attackers from reverse-engineering a substitute model. The limitations of this paper are that the proposed method may not be effective if the attacker conceals the query sample to look like a normal benign query, and the detection techniques may fail to capture this malicious behavior. Additionally, the proposed method requires the Deep Learning model to be processed before deployment, which may reduce the availability and utility of the model.</p>
<p>It should be noted that distinct datasets and feature extraction methods were employed for both models. Gong et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] employed model uncertainty to estimate the deep learning model&#x2019;s prediction accuracy. This model consists of two parts. The first part is a CNN model, which takes weblogs as inputs and extracts their features. The second is the Bayesian model. which is used as a classifier to classify each weblog containing a URL, response code, user agent, and source address into a web attack or normal log. This model achieved an accuracy of 98.38&#x0025;, a precision of 99.84&#x0025;, and a recall of 94.77&#x0025; as its performance metrics. Mo et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] presented an intrusion detection system based on Bi-LSTM (BL-IDS) model, which uses LSTMs and bidirectional recurrent neural networks to detect web attacks. The Word2vec toolbox converted the text into a word vector using the word embedding NLP technique (Skip-gram model). The CSIC 2010 HTTP dataset was used. The Bi-LSTM model was used to classify HTTP requests as legal or illegal for ten epochs of batch training methods. Almost all the models proposed to detect web application attacks classify attacks as having a binary classification (normal and malicious payloads). However, the proposed model is a multi-classification model that classifies each web attack according to type. Abramov et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] built (CODDLE) convolutional Deep Neural Network model to detect SQL injection and XSS attacks. Although CODDLE&#x2019;s best performance was up to 94&#x0025; accuracy, 99&#x0025; precision, and 93&#x0025; recall value, it used a separate dataset where each attack dataset was trained and tested separately by a binary classification model. Our model combined the two datasets into a single dataset, trained and tested the dataset with a multi-classification model, and achieved high-performance metrics values. The related works are summarized below in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1"><label>Table 1</label><caption><title>Existing prior studies about cross-site scripting (XSS) and SQL injection attacks</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left"/>
<th align="left">Problem statement</th>
<th align="left">Proposed model</th>
<th align="left">Results</th>
<th align="left">Drawbacks</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
<td align="left">Word embedding and CNN MLP algorithms were used to propose a new SQLIA prevention method. Denoise and decode HTTP requests, use Word2vec to create word embeddings of the decoded characters, train a CNN, MLP model, and use the classifier to identify fraudulent requests.</td>
<td align="left">User&#x2019;s HTTP request dataset. Word embedding created a word vector from the HTTP request. CBOW creates word embedding. MLP and Convolutional Neural Networks were used to train and test the dataset (CNN).</td>
<td align="left">Both models detected SQL injection attacks. CNN has 98.2&#x0025; accuracy and MLP 98.5.</td>
<td align="left">It detects only one type<break/>of web attack, which is SQLIA.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td align="left">This article suggests an Elastic-Pooling CNN-based (EP-CNN) model to detect SQL injection attacks in weblog-based web applications.</td>
<td align="left">Model proposed Word2vec converted the query to Vector. Three convolution kernels follow. After elastic pooling. Other convolution kernel layers passed outside this layer. This method produces a two-dimensional matrix without data trimming.</td>
<td align="left">It detected new SQL injection attacks by matching irregular characteristics with 99.93&#x0025; accuracy in the training set. Test set accuracy is 98.7&#x0025;.</td>
<td align="left">The needing to enhance this model to become multi-classification and cover other web attacks such as XSS attacks.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td align="left">DeepXSS is a deep learning approach for detecting XSS attacks based on the RNN LSTM algorithm and Word2vec technique.</td>
<td align="left">The Word2vec Continuous Bag of Words (CBOW) model mapped XSS payloads to feature vectors to convert input texts into numeric vectors. LSTM is used to train and test XSS payload datasets.</td>
<td align="left">The proposed model performed well with an F1 accuracy score of 98.7&#x0025;, a precision rate of 99.5&#x0025;, and a recall rate of 97.9&#x0025;.</td>
<td align="left">The model is not generalized to detect more web application attacks.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td align="left">They provide a deep learning method for identifying unusual requests. This method involves unsupervised RNN training (RNNs). The complicated recurrent unit (LSTM or GRU unit) to learn regular request patterns using only normal requests, followed by supervised training of a neural network classifier that uses RNN output to discriminate anomalous and legal requests.</td>
<td align="left">Tokenization precedes URL request. Word embedding then assigned real numbers to each word. After that, two RNN models&#x2014;LSTM and GRU&#x2014;were trained using typical requests to familiarize them with legitimate request patterns. The first RNN analyzes URL route structures, whereas the second analyzes query parameter structures. Finally, an MLP model trained on the preceding models&#x2019; probability sequences of URLs with the output label to distinguish between normal and anomalous URL occurrence probability sequences.</td>
<td align="left">This model achieves 97.8&#x0025; GRU and 98.4&#x0025; LSTM accuracy on the CSIC dataset. GRU and LSTM have 98.5&#x0025; and 98.3&#x0025; accuracy on WAF logs, respectively.</td>
<td align="left">Do not classify each URL attack based on type.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-6">6</xref>]</td>
<td align="left">Build Convolutional Deep Neural Network model to detect SQL injection and XSS attacks.</td>
<td align="left">SQLI/XSS symbols were encoded as command/symbol values using a customized pre-processing method. The first value is a simple numeric label, while the second is commend/symbols. Dataset payloads came from GitHub. Payloads are then converted into pairs (value and category). The CNN model trained and tested this dataset.</td>
<td align="left">The CNN model achieves up to 94&#x0025; accuracy, 99&#x0025; precision, and a 93&#x0025; recall value as the best performance.</td>
<td align="left">It used every attack as a separated dataset and did not group them into a single dataset.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td align="left">BL-IDS analyzes HTTP requests to detect Web threats using LSTMs and Bi-LSTMs.</td>
<td align="left">Word embedding NLP used the word2vec toolkit to convert text into word vectors (Skip-gram model). Used CSIC 2010 HTTP dataset. The Bi-LSTM model classified HTTP requests as normal or abnormal for ten batch training epochs.</td>
<td align="left">The model performs well with 98&#x0025; accuracy and 99&#x0025; precision.</td>
<td align="left">It did not classify each HTTP attack to its type.</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td align="left">A neural network-based SQL injection detection method is presented in this paper. They get accurate user URL access log data from the ISP to prove their strategy is real, effective, and feasible. After that, we statistically analyze normal and SQL injection data. Based on statistical findings, we train an MLP model with eight features. Using the Payloads dataset, this study detected SQLI with an LSTM model. And compare it to the MLP model&#x2019;s output.</td>
<td align="left">Based on statistical findings, they analyze URL text and create eight features. They used Payloads instead. By mapping characters with American Standard Code for Information Interchange (ASCII) code. An LSTM model is trained on this dataset with the right hyperparameters. Both models&#x2019; outcomes were compared.</td>
<td align="left">The MLP model&#x2019;s precision and accuracy are 99.55 and 99.86 percent after training. LSTM has a precision of 99.85&#x0025; and an accuracy of 98.69&#x0025;. MLP and LSTM accuracy tested at 99.67&#x0025; and 97.68&#x0025;, respectively.</td>
<td align="left">Different datasets and feature extraction methods were used for both models. Compared to other studies, the dataset is small. Only SQLi attacks are detected.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s3"><label>3</label><title>Methodology</title>
<p>In this section, we are going to illustrate our work and the proposed methodology. Our model starts by fitting on the textual datasets for both attack payloads: SQL injection and XSS. Then, we combine these two datasets into a single dataset formed from three classes. After that, label each class with a specific symbol. Different machine learning and deep learning algorithms will be used to multi-classify the attacks&#x2019; payloads. Different pre-processing techniques will be used to clean the data and convert the dataset from its textual form into a numeric form that can be easily manipulated by machine or deep learning algorithms.</p>
<p>In this research, we propose an intelligent web attack classification. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> depicts the methodology used in this paper to detect multi-class attacks.</p>
<fig id="fig-1"><label>Figure 1</label><caption><title>Flow graph of proposed approach</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-1.tif"/></fig>
<p>As shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, the methodology started by collecting the experimental dataset and constructing a multi-classification model that can detect two types of injection attacks and normal payloads. This model consists of various steps of pre-processing the textual dataset, encoding the payloads, and then converting the textual dataset into a numeric matrix using the principle of word embedding. The numeric dataset is split into a training dataset and a testing dataset. Finally, our model used the BiLSTM algorithm to classify the payloads into three groups. The following steps illustrate each phase used in our methodology.</p>
<sec id="s3_1"><label>3.1</label><title>Dataset Collection</title>
<p>Resources. XSS payloads have been collected from XSS_dataset [<xref ref-type="bibr" rid="ref-23">23</xref>] with 5282 normal payloads and 7368 abnormal payloads. At the same time, SQL injection payloads have been collected from the SQL injection dataset [<xref ref-type="bibr" rid="ref-24">24</xref>] and SQL-injection-payload-list in GitHub [<xref ref-type="bibr" rid="ref-25">25</xref>], including 3005 normal payloads and 1822 abnormal payloads.</p>
</sec>
<sec id="s3_2"><label>3.2</label><title>Data Pre-Processing</title>
<p>First, we merged the two datasets into a single dataset. Then, we labeled the payloads into three classes: 1 for XSS attacks, 2 for SQL injection attacks, and 0 for not-either-one payloads. Following that, we cleaned the payloads of special characters like &#x201C;, &#x2019;, &#x201D; &#x0024;, &#x0025;, &#x0026;, @, and so on. Finally, we used stemming text normalization to normalize each payload word.</p>
<p>For example, the following SQL injection and XSS payloads</p>
<p>&#x2018;and 1 in (select min(name) from sysobjects where xtype&#x2009;&#x003D;&#x2009;&#x2018;U&#x2019; and name &#x003E; &#x2018;.&#x2019;)&#x2013;</p>
<p>&#x003C;label onpointerdown&#x2009;&#x003D;&#x2009;alert (1)&#x2009;&#x003E;&#x2009;XSS&#x003C;/label&#x003E;</p>
<p>Will be after pre-processing as follows:</p>
<p>and 1 in selecting min name from sysobjects where xtype U and name</p>
<p>label onpointerdown alert 1 XSS label</p>
</sec>
<sec id="s3_3"><label>3.3</label><title>Word Embedding</title>
<p>Word embedding is a Natural Language Processing (NLP) technique that converts Natural Language text into a vector representing the text. Basically, word embedding maps a word to a vector using a dictionary [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p>In this article, first, we used one-hot encoding to convert every word into a number based on vocabulary size. This number represents the index of the word in the encoding matrix. Because word embedding inputs should be the same size, we pad the inputs with zeros (padding&#x2009;&#x003D;&#x2009;40). Finally, we used the TensorFlow embedding layer to perform word embedding and generate the embedding matrix.</p>
<sec id="s3_3_1"><label>3.3.1</label><title>Encoding</title>
<p>One-hot encoding is a way to change categorical variables into a format that deep learning algorithms can use to make better predictions. In the proposed model, we used one hot encoding with word embeddings. One hot encoding will convert the text into a sparse matrix with a lot of zeros, and only one value will indicate the location of this word in the predefined dictionary of words. We used word embedding with one-hot encoding to overcome the sparse matrix from the one-hot process into a dense matrix representing feature representation.</p>
</sec>
<sec id="s3_3_2"><label>3.3.2</label><title>Embedding Layer</title>
<p>A layer that can only be utilized as the initial layer of a model is known as an embedding layer. The layer converts positive integers (indices) into dense vectors of a predetermined size by multiplying them together. Word embeddings may be learned from text data and re-used in different projects at different times. They may also be trained as part of the process of fitting a neural network to text input. The embedding of a word in the learned vector space is referred to. The vector space location of a word is determined by the words surrounding it when it is employed.</p>
<p>Keras has an embedding layer that can be used for neural networks that work with textual data because each word has a unique number, and the input data needs to be encoded as an integer. This means that a number represents each word. A layer called the embedding layer is set up with random weights. It will learn an embedding for all of the words in the training dataset.</p>
<p>In our model, we set up an embedding layer as the flowing, input_dim&#x2009;&#x003D;&#x2009;5000, representing the vocabulary size in the text data, which means that each word will be encoded by a number from 0 to 4999 in the embedding matrix. output_dim&#x2009;&#x003D;&#x2009;40, which means each word will be placed in a vector space with 40 dimensions. input_length&#x2009;&#x003D;&#x2009;100, which represents the length of input sequences.</p>
</sec>
<sec id="s3_3_3"><label>3.3.3</label><title>Embedding Matrix</title>
<p>An embedding matrix is an idea that tries to solve this problem of how to show relationships. First, we choose a dimension of meaning. This can be a little bit random. Let us say we decide that all meaning can be mapped to a three-dimensional space that is not real. Theoretically, that would mean that each word would be a single point in a 3D space, and three numbers could describe the position of each word in that space (x, y, z). But in reality, meaning is too complex to fit well into three dimensions. Usually, we use something like 300 dimensions, and all words map to some point in this 300-dimensional hyperspace and are defined by 300 numbers. The 300 numbers that tell us what a word means are called the &#x201C;embedding&#x201D; for that word.</p>
</sec>
</sec>
<sec id="s3_4"><label>3.4</label><title>Dataset Splitting</title>
<p>There are a total of 17,478 samples in our dataset collection, which represents the attack&#x2019;s payloads. The total number of samples in the trainset reached 13,982, with about 3,496 samples used as a test set.</p>
</sec>
<sec id="s3_5"><label>3.5</label><title>Long Short-Term Memory (LSTM)</title>
<p>RNNs are artificial neural networks that perform well with sequential inputs. RNN is designed to connect events from the previous state to the current state by storing environmental data in an inner state [<xref ref-type="bibr" rid="ref-18">18</xref>]. RNNs achieved excellent results in dealing with most sequential data problems because they consider the sequence of the sentences or texts. So, it is a powerful tool for dealing with time series information that contains correlations between data points near each other in the sequence [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
<p>LSTM is an algorithm for solving the weaknesses of the RNN algorithm, which are vanishing and exploding gradient problems. The LSTM layer consists of memory blocks, which are recurrently connected blocks, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. Each one contains recurrently connected memory cells and three multiplicative units (input, output, and forget gates) that act as continuous analogs for the cells&#x2019; write, read, and reset operations [<xref ref-type="bibr" rid="ref-28">28</xref>]. A memory cell is a unit in LSTM networks that stores the state or the value. LSTM replaces nodes in hidden layers with one or more memory cells called memory blocks. Activation functions are used in the LSTM architecture instead of gates. The output from the previous layer is stored in gates, and functions determine whether the output will be used as input for the next hidden layer [<xref ref-type="bibr" rid="ref-29">29</xref>].
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>i</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>o</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>o</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>o</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mrow><mml:mover><mml:mi>c</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>i</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>c</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula>
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mtext>&#x00A0;</mml:mtext><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:mi>tanh</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<fig id="fig-2"><label>Figure 2</label><caption><title>LSTM layer with time series</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-2.tif"/></fig>
<p>The equation above and <xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrate the structure of the LSTM layer, where i_t, f_t, o_t are the input gate, forget gate, and output gate, respectively. Whereas c_t, <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mover><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x007E;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula>_t is the new state and candidate states of the memory cell, respectively, ct is the current state. The weight matrices are W_i W_c W_f W_o, and the biases are b_i b_f b_o. Sigmoid and hyperbolic tangent functions are identified as &#x03C3;() and tanh().</p>
<fig id="fig-3"><label>Figure 3</label><caption><title>LSTM architecture</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-3.tif"/></fig>
</sec>
<sec id="s3_6"><label>3.6</label><title>Bidirectional Long Short-Term Memory (BiLSTM)</title>
<p>The main idea of BiLSTM is that each training sequence is presented forward and backward to two independent recurrent networks coupled to the same output layer [<xref ref-type="bibr" rid="ref-28">28</xref>].</p>
<p>BiLSTM is designed to access both sentence directions (preceding and succeeding). Because it combines forward and backward LSTM layers, as illustrated in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>, The networks are trained over time using the backpropagation principle [<xref ref-type="bibr" rid="ref-30">30</xref>].</p>
<fig id="fig-4"><label>Figure 4</label><caption><title>BiLSTM model</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-4.tif"/></fig>
</sec>
</sec>
<sec id="s4"><label>4</label><title>Model Implementation and Experimental Setup</title>
<p>This section will go over the specifics of how this model will be fully implemented, with an explanation of the implemented model and the hyperparameter of the implemented model. Also, we explained the evaluation matrices used to evaluate our model. Moreover, the optimizer and loss functions are applied in this model.</p>
<p>The experimental setup was conducted on a computer with an Intel(R) Xeon(R) CPU @ 2.30&#x2005;GHz processor. The GPU was NVIDIA_SMI Tesla K80 with 12&#x2005;GB RAM. Python 3 was used as a programming language with Keras and the TensorFlow 2.6.0 framework.</p>
<sec id="s4_1"><label>4.1</label><title>Dataset Preparing</title>
<p>Before passing the data into the model, the data must be well prepared and cleaned. Several steps are used for preparing and pre-processing the dataset to produce cleaned data. First, we collected the dataset for both attacks separately. Then we combined the datasets into a single dataset. After that, we labeled the data into three groups: 0 for valid payloads, 1 for XSS attacks, and 2 for SQL injection attacks. The final step is skipping unwanted characters and cleaning the data using a Porter stemmer. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> illustrates the sequence of these steps.</p>
<fig id="fig-5"><label>Figure 5</label><caption><title>Dataset preparing process</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-5.tif"/></fig>
</sec>
<sec id="s4_2"><label>4.2</label><title>The Implementation of the Proposed Model</title>
<p>In our proposed model, we used a sequential model. We started this model by declaring the embedding layer with a parameter of 40 as embedding vector features and 100 as sentence length. This is followed by a bidirectional LSTM layer with 100 neurons in the forward and 100 neurons in the backward layers. Then drop out the layer to prevent overfitting. Finally, our model ends with a dense layer with three output neurons. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> illustrates the flow graph of the implementation of the proposed model. Moreover, <xref ref-type="fig" rid="fig-7">Fig. 7</xref> shows the sequential summary of the proposed model.</p>
<fig id="fig-6"><label>Figure 6</label><caption><title>Flow graph of the implementation of the proposed model</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-6.tif"/></fig><fig id="fig-7"><label>Figure 7</label><caption><title>Sequential summary of the proposed model</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-7.tif"/></fig>
</sec>
<sec id="s4_3"><label>4.3</label><title>Model Hyperparameters</title>
<p>In this phase, the hyperparameters were set. First, 40 features were determined to be the model&#x2019;s input, which means that the input size was set to 40 input layers. Thus, the LSTM hidden layers adopted one layer with 100 neurons for each direction, one layer as the forward layer and one as the backward layer of the BiLSTM scheme, and the output layer had three nodes. Each node represents a particular class. Thirty epochs and 128 batches with a learning rate of 0.01 were used to train the neural network. We have also selected Sigmoid as the activation function and utilised sparse_categorical_crossentropy as our loss function. Finally, Adam&#x2019;s optimizer was selected to update network weights iteratively based on training data. Moreover, it has many benefits over classical stochastic gradient descent. It is straightforward to implement, computationally efficient, has little memory requirements, and is well suited for large problems in terms of data and parameters. These hyperparameters are illustrated in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
<table-wrap id="table-2"><label>Table 2</label><caption><title>Hyperparameter of the model</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Hyper parameter</th>
<th align="left">Description</th>
<th align="left">Setting</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Vocabulary size</td>
<td align="left">The maximum range indicators of a particular word in the victor</td>
<td align="left">5000</td>
</tr>
<tr>
<td align="left">Sentence length</td>
<td align="left">The maximum length of the sentence</td>
<td align="left">100</td>
</tr>
<tr>
<td align="left">Embedding vector features</td>
<td align="left">No. of features to be extracted by embedding layer</td>
<td align="left">40</td>
</tr>
<tr>
<td align="left">Input size</td>
<td align="left">No. of the neurons at the input layer</td>
<td align="left">40</td>
</tr>
<tr>
<td align="left">Hidden layer</td>
<td align="left">No. of the hidden layers in the model</td>
<td align="left">1 (BiLSTM)</td>
</tr>
<tr>
<td align="left">Hidden size</td>
<td align="left">No. of the neurons at the hidden layer</td>
<td align="left">100 &#x002A; 2</td>
</tr>
<tr>
<td align="left">output size</td>
<td align="left">No. of the neurons at the output layer</td>
<td align="left">3</td>
</tr>
<tr>
<td align="left">Epochs</td>
<td align="left">No. of epochs</td>
<td align="left">30</td>
</tr>
<tr>
<td align="left">batch size</td>
<td align="left">Batch size</td>
<td align="left">128</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_4"><label>4.4</label><title>Evaluation Metrics</title>
<p>Accuracy, recall, F1 score, and precision are used for the evaluation phase. The four possible combinations are denoted by the symbols True Positive (TP), True Negative (TN), False Positive (FP), and False Negative (FN) in the model outputs for the test set data and the actual labels of the data. For the training and test sets, we assessed the performance of a neural network model on these four variables.
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mrow><mml:mtext>Accuracy</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>F</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mrow><mml:mtext>Precision&#xA0;</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>score&#xA0;</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mn>2</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mtext>Precision</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>Precision</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
</sec>
</sec>
<sec id="s5"><label>5</label><title>Results and Discussion</title>
<p>The total payloads in our dataset are 17,478 samples. The number of samples in the train set reached 13,982, and about 3,496 were used as a test set. As shown in <xref ref-type="table" rid="table-3">Table 3</xref>, the dataset was trained and tested using various models. Random Forest with StratifiedKFold with n_splits&#x2009;&#x003D;&#x2009;5, random_state&#x2009;&#x003D;&#x2009;100, and RandomizedSearchCV with n_jobs&#x2009;&#x003D;&#x2009;&#x2212;1, n_iter&#x2009;&#x003D;&#x2009;20, verbose&#x2009;&#x003D;&#x2009;2, Logistic Regression with tol&#x2009;&#x003D;&#x2009;1e&#x2212;4 and, Support Vector Machine (SVM) with kernel&#x2009;&#x003D;&#x2009;&#x201C;rbf&#x201D; and MLP. We found that our model (the BiLSTM) did an excellent job of classifying the payloads into three classes (e.g., cross-site scripting (XSS) attacks, injection attacks, and non-malicious payloads). A high level of performance was achieved at 99.2&#x0025; in terms of all evaluation metrics (e.g., accuracy, recall, precision, and F1 score).</p>
<table-wrap id="table-3"><label>Table 3</label><caption><title>Different models comparison based on performance</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Algorithm</th>
<th align="left">Accuracy</th>
<th align="left">Precision</th>
<th align="left">Recall</th>
<th align="left">F1 score</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Random forest</td>
<td align="left">97.88&#x0025;</td>
<td align="left">97.90&#x0025;</td>
<td align="left">97.88&#x0025;</td>
<td align="left">97.89&#x0025;</td>
</tr>
<tr>
<td align="left">SVM</td>
<td align="left">88.22&#x0025;</td>
<td align="left">88.76&#x0025;</td>
<td align="left">88.22&#x0025;</td>
<td align="left">88.36&#x0025;</td>
</tr>
<tr>
<td align="left">Logistic regression</td>
<td align="left">71.02&#x0025;</td>
<td align="left">73.49&#x0025;</td>
<td align="left">71.02&#x0025;</td>
<td align="left">70.57&#x0025;</td>
</tr>
<tr>
<td align="left">MLP</td>
<td align="left">90.99&#x0025;</td>
<td align="left">91.49&#x0025;</td>
<td align="left">90.99&#x0025;</td>
<td align="left">91.15&#x0025;</td>
</tr>
<tr>
<td align="left">Our model</td>
<td align="left">99.26&#x0025;</td>
<td align="left">99.26&#x0025;</td>
<td align="left">99.25&#x0025;</td>
<td align="left">99.24&#x0025;</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s5_1"><label>5.1</label><title>Confusion Matrix</title>
<p>Essentially, the confusion matrix is a cross table that records how many occurrences occurred between two raters, together with their true/actual classification and their expected classification [<xref ref-type="bibr" rid="ref-31">31</xref>].</p>
<p>The confusion matrix in <xref ref-type="fig" rid="fig-8">Fig. 8</xref> showed that the BiLSTM model did great in the three class detections. In class 1 (Not-ether-one), the overall samples were 1658; 1642 were classified correctly, whereas 16 were classified incorrectly. For class 2, that stands for XSS attacks. It was 14,766 samples. This model classified 1473 as an XSS attack, and only one sample was classified as an SQL injection attack. The third class is SQL injection attacks. Of the overall samples (364), 355 were classified correctly, whereas nine were classified incorrectly.</p>
<fig id="fig-8"><label>Figure 8</label><caption><title>Confusion metrix</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-8.tif"/></fig>
<p>The BiLSTM reached a loss of 0.03 in validation loss and 0.0020 in training loss at the 30th epoch. On the other hand, the accuracy at the 30th epoch reached 0.9926 in terms of validation accuracy and 0.9970 in training accuracy, as illustrated in <xref ref-type="fig" rid="fig-9">Figs. 9</xref> and <xref ref-type="fig" rid="fig-10">10</xref>.</p>
<fig id="fig-9"><label>Figure 9</label><caption><title>Loss curve</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-9.tif"/></fig><fig id="fig-10"><label>Figure 10</label><caption><title>Accuracy curve</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_40121-fig-10.tif"/></fig>
<p>As shown in <xref ref-type="table" rid="table-4">Table 4</xref>, the model work separately and detects XSS attacks with a precision of 0.9952, a recall of 0.9903, and an F1 score of 0.9927. The results were the same for a Not-ether-one payloads class. SQL injection attacks are also detected with a 0.9595 precision, a 0.9753 recall, and a 0.9673 F1 score.</p>
<table-wrap id="table-4"><label>Table 4</label><caption><title>BiLSTM performance of each class separately</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Class</th>
<th align="left">Precision</th>
<th align="left">Recall</th>
<th align="left">F1 score</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">XSS attacks</td>
<td align="left">0.9952</td>
<td align="left">0.9903</td>
<td align="left">0.9927</td>
</tr>
<tr>
<td align="left">SQL injection attacks</td>
<td align="left">0.9595</td>
<td align="left">0.9753</td>
<td align="left">0.9673</td>
</tr>
<tr>
<td align="left">Not-ether-one payloads</td>
<td align="left">0.9952</td>
<td align="left">0.9903</td>
<td align="left">0.9927</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s5_2"><label>5.2</label><title>Binary Classification for XSS and SQL Injection Attacks</title>
<p>For performing binary classifying on XSS and SQL injection attacks with the same model, we labeled both XSS and SQL injection payloads in the dataset as 1. In contrast, the normal payloads were labeled as 0. Binary_crossentropy was utilized as a loss function with an output layer of two neurons. The results shown in <xref ref-type="table" rid="table-5">Table 5</xref> point out that our model can also classify these two attacks as having malicious or non-malicious payloads.</p>
<table-wrap id="table-5"><label>Table 5</label><caption><title>Binary classification <italic>vs.</italic> multi-classification</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Classes</th>
<th align="left">Accuracy</th>
<th align="left">Precision</th>
<th align="left">Recall</th>
<th align="left">F1 score</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Binary classification</td>
<td align="left">99.17&#x0025;</td>
<td align="left">99.18&#x0025;</td>
<td align="left">99.16&#x0025;</td>
<td align="left">99.17&#x0025;</td>
</tr>
<tr>
<td align="left">Multi-classification</td>
<td align="left">99.26&#x0025;</td>
<td align="left">99.26&#x0025;</td>
<td align="left">99.25&#x0025;</td>
<td align="left">99.24&#x0025;</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s6"><label>6</label><title>Conclusion and Future Work</title>
<p>This paper develops a method based on deep learning to classify SQL injection and Cross-Site scripting attacks. This model used the BiLSTM recurrent neural network principle for training the payload dataset. The suggested model demonstrated that BiLSTM is extremely useful for detecting web application attacks such as XSS and SQL injection with high accuracy and efficiency. The results obtained in this study reached 99.260&#x0025;, 99.261&#x0025;, 99.259&#x0025;, and 99.248&#x0025; in terms of accuracy, precision, recall, and F1 score, respectively. For future work, we may extend this research to detect more attacks, such as phishing sites and Distributed Denial-of-Service (DDoS) Attacks. Furthermore, applying oversampling techniques to resolve the imbalanced dataset is highly suggested.</p>
</sec>
</body>
<back>
<ack>
<p>We gratefully thank King Saud University for Supporting Researchers Project Number (RSP2023R476), King Saud University, Riyadh, Saudi Arabia.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This work was funded by Researchers Supporting Project Number (RSP2023R476), King Saud University, Riyadh, Saudi Arabia.</p></sec>
<sec><title>Author Contributions</title>
<p>Abdulgbar A. R. Farea, Gehad Abdullah Amran contributed equally as co first authors. Study conception and design: Abdulgbar A. R. Farea, Gehad Abdullah Amran; data collection: Abdulgbar A. R. Farea, Gehad Abdullah Amran, Ebraheem Farea, Amerah Alabrah, Ahmed A. Abdulraheem, Muhammad Mursil and Mohammed A. A. Al-qaness; analysis and interpretation of results: Abdulgbar A. R. Farea, Gehad Abdullah Amran, Ebraheem Farea, Amerah Alabrah, Ahmed A. Abdulraheem, Muhammad Mursil and Mohammed A. A. Al-qaness; draft manuscript preparation: Abdulgbar A. R. Farea, Gehad Abdullah Amran. All authors reviewed the results and approved the final version of the manuscript.</p></sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>The data used to support the findings of this study are available from the corresponding author upon request.</p></sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p></sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>A. K.</given-names> <surname>Baranwal</surname></string-name></person-group>, &#x201C;<article-title>Approaches to detect SQL injection and XSS in web applications</article-title>,&#x201D; <source>EECE 571b, Term Survey Paper</source>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Johari</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Sharma</surname></string-name></person-group>, &#x201C;<article-title>A survey on web application vulnerabilities (SQLIA, XSS) exploitation and security engine for SQL injection</article-title>,&#x201D; in <conf-name>Int. Conf. on Communication Systems and Network Technologies, CSNT</conf-name>, <conf-loc>Rajkot, Gujarat, India</conf-loc>, pp. <fpage>453</fpage>&#x2013;<lpage>458</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S. K.</given-names> <surname>Mahmoud</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alfonse</surname></string-name>, <string-name><given-names>M. I.</given-names> <surname>Roushdy</surname></string-name> and <string-name><given-names>A. B. M.</given-names> <surname>Salem</surname></string-name></person-group>, &#x201C;<article-title>A comparative analysis of cross site scripting (XSS) detecting and defensive techniques</article-title>,&#x201D; in <conf-name>2017 Eighth Int. Conf. on Intelligent Computing and Information Systems (ICICIS)</conf-name>, <conf-loc>Cairo, Egypt</conf-loc>, pp. <fpage>36</fpage>&#x2013;<lpage>42</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Hasan</surname></string-name>, <string-name><given-names>A. M.</given-names> <surname>Zeki</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alharam</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Al-Mashhur</surname></string-name></person-group>, &#x201C;<article-title>Evaluation of SQL injection prevention methods</article-title>,&#x201D; in <conf-name>2019 8th Int. Conf. on Modeling Simulation and Applied Optimization, ICMSAO</conf-name>, <conf-loc>Manama, Bahrain</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Gupta</surname></string-name> and <string-name><given-names>B. B.</given-names> <surname>Gupta</surname></string-name></person-group>, &#x201C;<article-title>Cross-site scripting (XSS) attacks and defense mechanisms: Classification and state-of-the-art</article-title>,&#x201D; <source>International Journal of Systems Assurance Engineering and Management</source>, vol. <volume>8</volume>, pp. <fpage>512</fpage>&#x2013;<lpage>530</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Abaimov</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Bianchi</surname></string-name></person-group>, &#x201C;<article-title>CODDLE: Code-injection detection with deep learning</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>128617</fpage>&#x2013;<lpage>128627</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal">&#x201C;<article-title>OWASP Top 10 2017</article-title>,&#x201D; <source>OWASP Foundation Oracle Healthcare Data Repository Secure Development Guide</source>, vol. <volume>8</volume>, no. <issue>3</issue>, <year>2017</year>. <ext-link ext-link-type="uri" xlink:href="https://owasp.org/www-pdf-archive/OWASP_Top_10-2017_%28en%29.pdf.pdf">https://owasp.org/www-pdf-archive/OWASP_Top_10-2017_%28en%29.pdf.pdf</ext-link></mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Fang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>DeepXSS: Cross site scripting detection based on deep learning</article-title>,&#x201D; in <conf-name>Proc. of the 2018 Int. Conf. on Computing and Artificial Intelligence</conf-name>, <conf-loc>Chengdu, China</conf-loc>, pp. <fpage>47</fpage>&#x2013;<lpage>51</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Qiu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Lian</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Detection of SQL injection based on artificial neural network</article-title>,&#x201D; <source>Knowledge-Based Systems</source>, vol. <volume>190</volume>, pp. <fpage>105528</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. T.</given-names> <surname>Muslihi</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Alghazzawi</surname></string-name></person-group>, &#x201C;<article-title>Detecting SQL injection on web application using deep learning techniques: A systematic literature review</article-title>,&#x201D; in <conf-name>2020 Third Int. Conf. on Vocational Education and Electrical Engineering (ICVEE)</conf-name>, <conf-loc>Surabaya, Indonesia</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Yan</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Wu</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Zhao</surname></string-name></person-group>, &#x201C;<article-title>SQL injection attack detection and prevention techniques using deep learning</article-title>,&#x201D; <source>Journal of Physics: Conference Series</source>, <publisher-loc>Changsha, China</publisher-loc>, vol. <volume>1757</volume>, no. <issue>1</issue>, pp. <fpage>012055</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V. S.</given-names> <surname>Stency</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Mohanasundaram</surname></string-name></person-group>, &#x201C;<article-title>A study on XSS attacks: Intelligent detection methods</article-title>,&#x201D; <source>Journal of Physics: Conference Series</source>, vol. <volume>1767</volume>, no. <issue>1</issue>, pp. <fpage>12047</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Xie</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Fu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Xu</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Guo</surname></string-name></person-group>, &#x201C;<article-title>SQL injection detection for web applications based on elastic-pooling CNN</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>151475</fpage>&#x2013;<lpage>151481</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Hasan</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Balbahaith</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Tarique</surname></string-name></person-group>, &#x201C;<article-title>Detection of SQL injection attacks: A machine learning approach</article-title>,&#x201D; in <conf-name>2019 Int. Conf. on Electrical and Computing Technologies and Applications (ICECTA)</conf-name>, <conf-loc>Ras Al Khaimah, United Arab Emirates</conf-loc>, <publisher-name>IEEE</publisher-name>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Abdalla</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Elsamani</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abdallah</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Elhabob</surname></string-name></person-group>, &#x201C;<article-title>An efficient model to detect and prevent SQL injection attack</article-title>,&#x201D; <source>Journal of Karary University for Engineering and Science</source>, pp. <fpage>1858</fpage>&#x2013;<lpage>8034</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Sharma</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Zavarsky</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Butakov</surname></string-name></person-group>, &#x201C;<article-title>Machine learning based intrusion detection system for web-based attacks</article-title>,&#x201D; in <conf-name>2020 IEEE 6th Int. Conf. on Big Data Security on Cloud (BigDataSecurity), IEEE Int. Conf. on High Performance and Smart Computing,(HPSC) and IEEE Int. Conf. on Intelligent Data and Security (IDS)</conf-name>, <conf-loc>Baltimore, MD, USA</conf-loc>, <publisher-name>IEEE</publisher-name>, pp. <fpage>227</fpage>&#x2013;<lpage>230</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Kaur</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Malik</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Samuel</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Jaafar</surname></string-name></person-group>, &#x201C;<article-title>Detecting blind cross-site scripting attacks using machine learning</article-title>,&#x201D; in <conf-name>Proc. of the 2018 Int. Conf. on Signal Processing and Machine Learning</conf-name>, <conf-loc>Shanghai, China</conf-loc>, pp. <fpage>22</fpage>&#x2013;<lpage>25</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Liang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhao</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Ye</surname></string-name></person-group>, &#x201C;<article-title>Anomaly-based web attack detection: A deep learning approach</article-title>,&#x201D; in <conf-name>Proc. of the 2017 VI Int. Conf. on Network, Communication and Computing</conf-name>, <conf-loc>Kunming, China</conf-loc>, pp. <fpage>80</fpage>&#x2013;<lpage>85</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J. L.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Peng</surname></string-name>, <string-name><given-names>Y. S.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name> and <string-name><given-names>Q. H.</given-names> <surname>Hong</surname></string-name></person-group>, &#x201C;<article-title>APMSA: Adversarial perturbation against model stealing attacks</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>18</volume>, pp. <fpage>1667</fpage>&#x2013;<lpage>1679</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Gong</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Bi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>He</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Sheng</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Estimating web attack detection via model uncertainty from inaccurate annotation</article-title>,&#x201D; in <conf-name>6th IEEE Int. Conf. on Cyber Security and Cloud Computing, CSCloud 2019 and 5th IEEE Int. Conf. on Edge Computing and Scalable Cloud, EdgeCom 2019</conf-name>, <conf-loc>Paris, France</conf-loc>, pp. <fpage>53</fpage>&#x2013;<lpage>58</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Mo</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Security and privacy in new computing environments</article-title>,&#x201D; in <conf-name>SPNCE: Int. Conf. on Security and Privacy in New Computing Environments</conf-name>, <conf-loc>Tianjin, China</conf-loc>, vol. <volume>284</volume>, pp. <fpage>96</fpage>&#x2013;<lpage>104</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Saiyu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Long</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>Bl-IDS: Detecting web attacks using Bi-LSTM model based on deep learning</article-title>,&#x201D; in <conf-name>Security and Privacy in New Computing Environments: Second EAI Int. Conf., SPNCE 2019</conf-name>, <conf-loc>Tianjin, China</conf-loc>, pp. <fpage>551</fpage>&#x2013;<lpage>563</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Kaggle</collab></person-group>, <source>Cross Site Scripting XSS Dataset for Deep Learning</source>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/syedsaqlainhussain/cross-site-scripting-xss-dataset-for-deep-learning">https://www.kaggle.com/syedsaqlainhussain/cross-site-scripting-xss-dataset-for-deep-learning</ext-link></mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Kaggle</collab></person-group>, <source>SQL Injection Dataset</source>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/syedsaqlainhussain/sql-injection-dataset">https://www.kaggle.com/syedsaqlainhussain/sql-injection-dataset</ext-link></mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="other"><source>SQL Injection Payload List</source>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://github.com/payloadbox/sql-injection-payload-list">https://github.com/payloadbox/sql-injection-payload-list</ext-link></mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. V.</given-names> <surname>Nimkar</surname></string-name> and <string-name><given-names>D. R.</given-names> <surname>Kubal</surname></string-name></person-group>, &#x201C;<article-title>A survey on word embedding techniques and semantic similarity for paraphrase identification</article-title>,&#x201D; <source>International Journal of Computational Systems Engineering</source>, vol. <volume>5</volume>, no. <issue>1</issue>, pp. <fpage>36</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Schuster</surname></string-name> and <string-name><given-names>K. K.</given-names> <surname>Paliwal</surname></string-name></person-group>, &#x201C;<article-title>Bidirectional recurrent neural networks</article-title>,&#x201D; <source>IEEE Transactions on Signal Processing</source>, vol. <volume>45</volume>, no. <issue>11</issue>, pp. <fpage>2673</fpage>&#x2013;<lpage>2681</lpage>, <year>1997</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Hu</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>Bidirectional long short-term memory networks for relation classification</article-title>,&#x201D; in <conf-name>Proc. of the 29th Pacific Asia Conf. on Language, Information and Computation</conf-name>, <conf-loc>Shanghai, China</conf-loc>, pp. <fpage>73</fpage>&#x2013;<lpage>78</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Hochreiter</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Schmidhuber</surname></string-name></person-group>, &#x201C;<article-title>LSTM can solve hard long time lag problems</article-title>,&#x201D; <source>Advances in Neural Information Processing Systems</source>, vol. <volume>9</volume>, pp. <fpage>473</fpage>&#x2013;<lpage>479</lpage>, <year>1997</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Guo</surname></string-name></person-group>, &#x201C;<article-title>Bidirectional LSTM with attention mechanism and convolutional layer for text classification</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>337</volume>, pp. <fpage>325</fpage>&#x2013;<lpage>338</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Grandini</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Bagli</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Visani</surname></string-name></person-group>, &#x201C;<article-title>Metrics for multi-class classification: An overview</article-title>,&#x201D; arXiv: 2008.05756, <year>2020</year>.</mixed-citation></ref>
</ref-list>
</back></article>