EAV123/SQL_Injection_Detection
0
1import streamlit as st2import tensorflow as tf3from tensorflow.keras.models import load_model4from tensorflow.keras.preprocessing.text import Tokenizer5from tensorflow.keras.preprocessing.sequence import pad_sequences6import pickle7import re8import time9import numpy as np10from sklearn.ensemble import RandomForestClassifier11from sklearn.svm import SVC12 13# Load models and preprocessing components14@st.cache_resource15def load_components():16 # Load deep learning models17 cnn_model = load_model('cnn_model.h5')18 lstm_model = load_model('lstm_model.h5')19 # Load traditional ML models20 with open('rf_model.pkl', 'rb') as f:21 rf_model = pickle.load(f)22 with open('svm_model.pkl', 'rb') as f:23 svm_model = pickle.load(f)24 # Load tokenizer and vectorizer25 with open('sql_tokenizer.pkl', 'rb') as f:26 tokenizer_data = pickle.load(f)27 with open('tfidf_vectorizer.pkl', 'rb') as f:28 tfidf_vectorizer = pickle.load(f)29 return {30 'cnn_model': cnn_model,31 'lstm_model': lstm_model,32 'rf_model': rf_model,33 'svm_model': svm_model,34 'tokenizer': tokenizer_data['tokenizer'],35 'max_sequence_length': tokenizer_data['max_sequence_length'],36 'tfidf_vectorizer': tfidf_vectorizer37 }38 39# Try to load all components40try:41 components = load_components()42 model_loading_error = None43except Exception as e:44 model_loading_error = str(e)45 components = None46 47# Preprocess functions48def preprocess_query_for_deep_learning(query, tokenizer, max_sequence_length):49 sequences = tokenizer.texts_to_sequences([query])50 padded = pad_sequences(sequences, maxlen=max_sequence_length, padding='post')51 return padded52 53def preprocess_query_for_traditional_ml(query, tfidf_vectorizer):54 return tfidf_vectorizer.transform([query])55 56# Define improved regex patterns for SQL injection attempts57SQL_INJECTION_PATTERNS = [58 # SQL comment syntax that follows a quote (likely injection)59 r"(?i)'.*--",60 61 # Quote followed by OR/AND with comparison (classic injection pattern)62 r"(?i)'\s*(OR|AND)\s*['\d\w]+=\s*['\d\w]+",63 64 # SQL Comment without preceding from a query context65 r"(?i)(\s|^)--",66 67 # Multiple query execution with semicolon68 r"(?i)'.*;.*--",69 70 # UNION-based injections71 r"(?i)'\s*UNION\s+(ALL\s+)?SELECT",72 73 # Time-delay attacks74 r"(?i)'\s*;\s*WAITFOR\s+DELAY",75 76 # DROP/ALTER table attacks77 r"(?i)'\s*;\s*(DROP|ALTER)",78 79 # Quote followed by a true condition80 r"(?i)'\s*OR\s*'?\d+'?\s*=\s*'?\d+'?",81 82 # Quote followed by always true condition like 1=183 r"(?i)'\s*OR\s*(['\"]\d+['\"])=(['\"]\d+['\"])",84 85 # Batch queries86 r"(?i);\s*(SELECT|INSERT|UPDATE|DELETE|DROP)",87 88 # CAST attacks89 r"(?i)CAST\s*\(.+AS\s+.+\)",90 91 # Typical SQL function calls in injections92 r"(?i)'\s*;\s*(EXEC|EXECUTE).*",93]94 95# Safe SQL patterns that should not trigger false positives96SAFE_SQL_PATTERNS = [97 # Standard SELECT query98 r"(?i)^SELECT\s+[\w\d\s,*]+\s+FROM\s+[\w\d]+(\s+WHERE\s+[\w\d\s=<>']+)?$",99 100 # Standard INSERT query101 r"(?i)^INSERT\s+INTO\s+[\w\d]+\s*\([^)]+\)\s*VALUES\s*\([^)]+\)$",102 103 # Standard UPDATE query104 r"(?i)^UPDATE\s+[\w\d]+\s+SET\s+[\w\d\s=',]+(\s+WHERE\s+[\w\d\s=<>']+)?$",105]106 107 108# Rule-based detection function109def detect_sql_injection_with_regex(query):110 for pattern in SAFE_SQL_PATTERNS:111 if re.search(pattern, query.strip()):112 return False, None113 for pattern in SQL_INJECTION_PATTERNS:114 match = re.search(pattern, query)115 if match:116 return True, match.group(0)117 return False, None118 119# Ensemble prediction function120def predict_with_ensemble(query, components):121 # Random Forest prediction122 query_tfidf = preprocess_query_for_traditional_ml(query, components['tfidf_vectorizer'])123 rf_pred = int(components['rf_model'].predict(query_tfidf)[0])124 # SVM prediction125 svm_pred = int(components['svm_model'].predict(query_tfidf)[0])126 # CNN prediction127 query_padded = preprocess_query_for_deep_learning(query, components['tokenizer'], components['max_sequence_length'])128 cnn_probability = components['cnn_model'].predict(query_padded)[0][0]129 cnn_pred = int(cnn_probability > 0.5)130 # LSTM prediction131 lstm_probability = components['lstm_model'].predict(query_padded)[0][0]132 lstm_pred = int(lstm_probability > 0.5)133 # Count votes134 votes = [rf_pred, svm_pred, cnn_pred, lstm_pred]135 vote_count = {0: votes.count(0), 1: votes.count(1)}136 return {137 'rf': rf_pred,138 'svm': svm_pred,139 'cnn': {'prediction': cnn_pred, 'probability': float(cnn_probability)},140 'lstm': {'prediction': lstm_pred, 'probability': float(lstm_probability)},141 'vote_count': vote_count142 }143 144# Initialize session state145if 'analysis_stage' not in st.session_state:146 st.session_state.analysis_stage = 0147if 'regex_result' not in st.session_state:148 st.session_state.regex_result = None149if 'ensemble_result' not in st.session_state:150 st.session_state.ensemble_result = None151 152# App title and description153st.title("🛡️ SQL Injection Detection")154st.markdown("""155This application uses a multi-layered approach to detect potentially malicious SQL queries:1561. **Rule-based detection** using improved regex patterns.1572. **Ensemble learning** with majority voting from 4 models:158 - Random Forest159 - Support Vector Machine160 - Convolutional Neural Network161 - Long Short-Term Memory Network.162""")163 164# Display warning if models couldn't be loaded165if model_loading_error:166 st.warning(f"⚠️ Some models could not be loaded. The application will only use rule-based detection. Error: {model_loading_error}")167 168# Example queries in a dropdown169example_categories = {170 "Benign SQL Queries": [171 "SELECT * FROM users WHERE username='admin'",172 "SELECT id, name, price FROM products WHERE category_id=5",173 "SELECT COUNT(*) FROM orders WHERE date > '2023-01-01'",174 "INSERT INTO logs (user_id, action) VALUES (42, 'login')",175 "UPDATE customers SET last_login='2023-06-15' WHERE id=101",176 "DELETE FROM sessions WHERE last_activity < '2023-01-01'",177 "SELECT email FROM subscribers WHERE active=1",178 "INSERT INTO feedback (user_id, message) VALUES (87, 'Great service!')",179 "UPDATE inventory SET stock = stock - 1 WHERE product_id = 300",180 "SELECT name FROM employees WHERE department = 'Sales'",181 "SELECT AVG(rating) FROM reviews WHERE product_id = 55",182 "INSERT INTO audit_log (timestamp, event) VALUES (CURRENT_TIMESTAMP, 'update')",183 "SELECT * FROM appointments WHERE doctor_id = 10 AND status = 'confirmed'",184 "UPDATE settings SET value='dark' WHERE key='theme'",185 "SELECT DISTINCT city FROM customers WHERE country='USA'",186 "DELETE FROM cart_items WHERE user_id=12 AND product_id=78",187 "SELECT MAX(salary) FROM employees WHERE role='manager'",188 "INSERT INTO payments (user_id, amount, method) VALUES (33, 99.99, 'credit')",189 "UPDATE products SET price = price * 1.1 WHERE category_id = 7",190 "SELECT * FROM messages WHERE sender_id = 5 AND is_read = 0"191 ],192 "Malicious SQL Queries": [193 "' OR 1=1 --",194 "admin'; DROP TABLE users; --",195 "SELECT * FROM users WHERE username='' UNION SELECT username,password FROM admin_users --",196 "'; WAITFOR DELAY '0:0:10' --",197 "admin' OR '1'='1",198 "' OR 'a'='a",199 "' OR 1=1#",200 "' OR 1=1/*",201 "admin'--",202 "'; EXEC xp_cmdshell('dir'); --",203 "' OR EXISTS(SELECT * FROM users WHERE username = 'admin') --",204 "1; DROP TABLE sessions --",205 "'; SHUTDOWN --",206 "' OR SLEEP(5) --",207 "' AND 1=(SELECT COUNT(*) FROM users) --",208 "admin' AND SUBSTRING(password, 1, 1) = 'a' --",209 "' UNION ALL SELECT NULL,NULL,NULL --",210 "0' OR 1=1 ORDER BY 1 --",211 "1' AND (SELECT COUNT(*) FROM users) > 0 --",212 "' OR (SELECT ASCII(SUBSTRING(password,1,1)) FROM users WHERE username='admin') > 64 --"213 ]214}215 216 217category = st.selectbox("Choose query category:", options=list(example_categories.keys()))218example = st.selectbox("Select an example:", options=example_categories[category])219query_source = st.radio("Query source:", ["Use selected example", "Enter my own query"])220query = example if query_source == "Use selected example" else st.text_area("Enter SQL Query:", placeholder="Type your SQL query here...")221 222# Analysis process223if st.button("Start Analysis") and query:224 st.session_state.analysis_stage = 1225 with st.spinner("Running rule-based detection..."):226 time.sleep(0.5) # Simulate processing time227 is_malicious, matched_pattern = detect_sql_injection_with_regex(query)228 st.session_state.regex_result = (is_malicious, matched_pattern)229 230# Rule-based analysis results231if st.session_state.analysis_stage >= 1 and st.session_state.regex_result is not None:232 is_malicious, matched_pattern = st.session_state.regex_result233 st.subheader("Step 1: Rule-Based Detection")234 if is_malicious:235 st.error("🚨 SQL Injection Detected (Rule-Based)!")236 st.warning(f"Matched pattern: `{matched_pattern}`")237 else:238 st.success("✅ No SQL injection patterns detected using rules")239 240 proceed = st.radio("Proceed with ensemble detection?", ["Yes", "No"], index=0)241 if proceed == "Yes" and not model_loading_error:242 if st.button("Run Ensemble Analysis"):243 st.session_state.analysis_stage = 2244 with st.spinner("Running ensemble models..."):245 time.sleep(1) # Simulate processing time246 ensemble_results = predict_with_ensemble(query, components)247 st.session_state.ensemble_result = ensemble_results248 249# Ensemble analysis results250if st.session_state.analysis_stage >= 2 and st.session_state.ensemble_result is not None:251 results = st.session_state.ensemble_result252 st.subheader("Step 2: Ensemble Model Detection")253 vote_benign = results['vote_count'][0]254 vote_malicious = results['vote_count'][1]255 256 # Create columns for voting visualization257 col1, col2 = st.columns(2)258 with col1:259 st.metric("Safe Votes", vote_benign)260 with col2:261 st.metric("Malicious Votes", vote_malicious)262 263 # Progress bar for malicious ratio264 vote_ratio = vote_malicious / (vote_benign + vote_malicious)265 st.progress(vote_ratio, text=f"Malicious vote ratio: {vote_ratio*100:.0f}%")266 267 # Display individual model results268 st.markdown("### Individual Model Results")269 270 model_cols = st.columns(4)271 272 with model_cols[0]:273 st.markdown("**Random Forest**")274 if results['rf'] == 1:275 st.error("⚠️ Malicious")276 else:277 st.success("✅ Safe")278 279 with model_cols[1]:280 st.markdown("**SVM**")281 if results['svm'] == 1:282 st.error("⚠️ Malicious")283 else:284 st.success("✅ Safe")285 286 with model_cols[2]:287 st.markdown("**CNN**")288 cnn_prob = results['cnn']['probability'] * 100289 if results['cnn']['prediction'] == 1:290 st.error(f"⚠️ Malicious ({cnn_prob:.1f}%)")291 else:292 st.success(f"✅ Safe ({100-cnn_prob:.1f}%)")293 294 with model_cols[3]:295 st.markdown("**LSTM**")296 lstm_prob = results['lstm']['probability'] * 100297 if results['lstm']['prediction'] == 1:298 st.error(f"⚠️ Malicious ({lstm_prob:.1f}%)")299 else:300 st.success(f"✅ Safe ({100-lstm_prob:.1f}%)")301 302 303 # Final ensemble verdict304 st.markdown("### Ensemble Verdict")305 if vote_benign > 3:306 st.success("✅ Query deemed safe by majority vote (>3 safe votes)")307 elif vote_malicious > 3:308 st.error("🚨 SQL Injection Detected by Majority Vote (>3 malicious votes)")309 else:310 st.warning("⚠️ Ambiguous result: Votes split (≤3 each). Please cross-check manually.")311 312 # Final verdict combining both approaches313 st.subheader("Final Analysis")314 is_malicious_regex, _ = st.session_state.regex_result315 is_malicious_ensemble = vote_malicious > 3316 if is_malicious_regex or is_malicious_ensemble:317 st.error("⚠️ This query appears malicious. Review immediately!")318 elif vote_benign > 3:319 st.success("✅ Query appears safe based on multi-layer analysis")320 else:321 st.warning("⚠️ Ambiguous result - manual verification required")322 323 if st.button("Analyze Another Query"):324 st.session_state.analysis_stage = 0325 st.session_state.regex_result = None326 st.session_state.ensemble_result = None327 st.rerun() 328 329# Sidebar with additional info330with st.sidebar:331 st.header("About This App")332 st.markdown("""333 ### Multi-Layer Detection Process334 335 1. **Rule-Based Detection**336 - Fast, pattern-matching approach337 - Uses improved regex to identify SQL injection patterns338 - Reduces false positives with safe pattern recognition339 340 2. **Ensemble Detection**341 - Combines 4 different machine learning models:342 - Random Forest343 - Support Vector Machine (SVM)344 - Convolutional Neural Network (CNN)345 - Long Short-Term Memory Network (LSTM)346 - Final decision by majority voting347 """)348 349 st.markdown("### Machine Learning Architecture")350 st.code("""351 # Traditional ML352 - Random Forest (n_estimators=100)353 - SVM (kernel='linear')354 355 # CNN Architecture356 Sequential([357 Embedding(input_dim=10000, output_dim=128),358 Conv1D(filters=64, kernel_size=3, activation='relu'),359 MaxPooling1D(pool_size=2),360 Dropout(0.5),361 Conv1D(filters=128, kernel_size=3, activation='relu'),362 MaxPooling1D(pool_size=2),363 Flatten(),364 Dense(64, activation='relu'),365 Dropout(0.5),366 Dense(1, activation='sigmoid')367 ])368 369 # LSTM Architecture370 Sequential([371 Embedding(input_dim=10000, output_dim=128),372 Bidirectional(LSTM(64, return_sequences=True)),373 Dropout(0.5),374 Bidirectional(LSTM(32)),375 Dropout(0.5),376 Dense(32, activation='relu'),377 Dense(1, activation='sigmoid')378 ])379 """)380 381 st.markdown("### How It Works")382 st.markdown("""383 1. **Step 1:** Rule-based patterns scan for known SQL injection techniques384 2. **Step 2:** Ensemble of 4 models evaluates the query structure385 3. **Final Analysis:** Combined verdict from both approaches386 """)387 388 st.markdown("---")389 st.warning("**Note:** This is a demonstration tool, not a replacement for proper security measures.")390 391# Footer392st.markdown("---")393st.markdown("""394<style>395.footer {396 position: fixed;397 left: 0;398 bottom: 0;399 width: 100%;400 background-color: white;401 color: black;402 text-align: center;403 padding: 10px;404 border-top: 1px solid #e5e5e5;405}406</style>407<div class="footer">408<p>Developed with ❤️ using Streamlit | SQL Injection Detection System</p>409</div>410""", unsafe_allow_html=True)