ระบบตรวจจับและป้องกันการโจมตีด้วยการแทรกคำสั่งเอสคิวแอลจากข้อมูล ไฟล์บันทึกเหตุการณ์ สำหรับเว็บแอปพลิเคชันที่พัฒนาด้วยภาษาพีเอชพี
DOI:
https://doi.org/10.65205/jcct.2026.e3560คำสำคัญ:
การตรวจจับการโจมตีด้วยการแทรกคำสั่งเอสคิวแอล, การวิเคราะห์ไฟล์บันทึกเหตุการณ์, การให้คะแนนน้ำหนัก, ความมั่นคงปลอดภัยเว็บแอปพลิเคชันบทคัดย่อ
งานวิจัยนี้มีวัตถุประสงค์เพื่อ 1) เพื่อศึกษารูปแบบการโจมตี SQL Injection ที่เกิดขึ้นจริงจากข้อมูล Logfile ของระบบ 2) เพื่อออกแบบและพัฒนาระบบตรวจจับและป้องกัน SQL Injection แบบอัตโนมัติด้วยเทคนิค Rule-based 3) เพื่อประเมินประสิทธิภาพของระบบ วิธีดำเนินการวิจัยแบ่งออกเป็น 3 ระยะ เริ่มจาก 1) การรวบรวมและวิเคราะห์ข้อมูลจาก Logfile จริง ในอดีตจำนวน 4,649 รายการ เพื่อสร้างกฎการตรวจจับ 2) การทดสอบความถูกต้องกับชุดข้อมูลใหม่ จำนวน 4,312 รายการ และ 3) ประเมินประสิทธิภาพของระบบด้วยตัวชี้วัด TP, FP, FN และ TN โดยประเมินผลจากการใช้งานจริงบนระบบสารสนเทศด้านวัฒนธรรมและแผนที่วัฒนธรรม เป็นเวลา 830 วัน ผลการวิจัย พบว่าระบบมีความแม่นยำ (Accuracy) และค่า F1-Score สูงถึงร้อยละ 100 ในทุกระยะการทดสอบ โดยในระยะใช้งานจริงสามารถตรวจจับความพยายามในการโจมตีได้ทั้งสิ้น 25,660 ครั้ง นอกจากนี้ ผลการวิจัยชี้ให้เห็นว่าอัตราการโจมตีเฉลี่ยต่อวันลดลงอย่างมีนัยสำคัญภายหลังการติดตั้งระบบ ซึ่งแสดงถึงประสิทธิภาพในการยับยั้งการโจมตี และความสามารถในการตรวจจับเทคนิคการหลบเลี่ยง ได้อย่างมีประสิทธิภาพ ช่วยยกระดับความมั่นคงปลอดภัยให้กับระบบสารสนเทศในระยะยาว
Downloads
เอกสารอ้างอิง
Alghawazi, M., Alghazzawi, D., & Alarifi, S. (2022). Detection of SQL Injection Attack Using Machine Learning Techniques: A Systematic Literature Review. Journal of Cybersecurity and Privacy, 2(4), 764–777. https://doi.org/10.3390/jcp2040039
Arnap, A., & Kusrini. (2024). Enhancing SQL Injection Attack Detection Using Naïve Bayes and SMOTE Method on Imbalanced Datasets. Journal of Artificial Intelligence and Engineering Applications, 4(1), 74–81. https://doi.org/10.59934/jaiea.v4i1.559
Das, D., Sharma, U., & Bhattacharyya, D. K. (2019). Defeating SQL Injection Attack in Authentication Security: An Experimental Study. International Journal of Information Security, 18(1), 1–22. https://doi.org/10.1007/s10207-017-0393-x
Fu, H., Guo, C., Jiang, C., Ping, Y., & Lv, X. (2023). SDSIOT: An SQL Injection Attack Detection and Stage Identification Method Based on Outbound Traffic. Electronics, 12(11), 2472. https://doi.org/10.3390/electronics12112472
Hofesh, B. (2022). SQL Injection Attack: How It Works, Examples and Prevention. Bright Security. https://brightsec.com/blog/sql-injection-attack
Kaur, J., Garg, U., & Bathla, G. (2023). Detection of Cross-Site Scripting (XSS) Attacks Using Machine Learning Techniques: A Review. Artificial Intelligence Review, 56(11), 12725-12769. https://doi.org/10.1007/s10462-023-10433-3
Lu, D., Fei, J., & Liu, L. (2023). A Semantic Learning-Based SQL Injection Attack Detection Technology. Electronics, 12(6), 1344. https://doi.org/10.3390/electronics12061344
Muhammad, T., & Ghafory, H. (2022). SQL Injection Attack Detection Using Machine Learning Algorithm. Mesopotamian Journal of CyberSecurity, 2022, 5-17. https://doi.org/10.58496/MJCS/2022/002
Mutedi, A., & Tjahjono, B. (2022). Systematic Literature Review: Preventing SQL Injection Attacks Using Tools OWASP CSR Web Application Firewall. Jurnal Informatika Universitas Pamulang, 7(1), 151-156.
OWASP. (2021). Introduction: Welcome to the OWASP Top 10-2021. https://owasp.org/Top10/2021/A00_2021_Introduction
Pan, Y., Sun, F., Teng, Z., White, J., Schmidt, D. C., Staples, J., & Krause, L. (2019). Detecting Web Attacks with End-to-End Deep Learning. Journal of Internet Services and Applications, 10(1), 16. https://doi.org/10.1186/s13174-019-0115-x
Securities and Exchange Commission. (2023). Cyber Attack Trends 2023, Based on Data from the National Cyber Security Agency. https://www.sec.or.th/th/pages/cyberresilience-statistics-2566.aspx (In Thai)
ดาวน์โหลด
เผยแพร่แล้ว
รูปแบบการอ้างอิง
ฉบับ
ประเภทบทความ
สัญญาอนุญาต
ลิขสิทธิ์ (c) 2026 วารสารคอมพิวเตอร์และเทคโนโลยีสร้างสรรค์

อนุญาตภายใต้เงื่อนไข Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.





















