USENIX Security2023Top-tier venue
SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement Learning
Salim Al Wahaibi, Myles Foley, Sergio Maffeis
Abstract
Web security scanners are used to discover SQL injection vulnerabilities in deployed web applications. Scanners tend to use static rules to cover the most common injection cases, missing diversity in their payloads, leading to a high volume of requests and false negatives. Moreover, scanners often rely on the presence of error messages or other significant feedback on the target web pages, as a result of additional insecure programming practices by web developers. In this paper we develop SQIRL, a novel approach to detecting SQL injection vulnerabilities based on deep reinforcement learning, using multiple worker agents and grey-box feedback. Each worker intelligently fuzzes the input fields discovered by an automated crawling component. This approach generates a more varied set of payloads than existing scanners, leading to the discovery of more vulnerabilities. Moreover, SQIRL attempts fewer payloads, because they are generated in a targeted fashion. SQIRL finds all vulnerabilities in our microbenchmark for SQL injection, with substantially fewer requests than most of the state-of-the-art scanners compared with. It also significantly outperforms other scanners on a set of 14 production grade web applications, discovering 33 vulnerabilities, with zero false positives. We have responsibly disclosed 22 novel vulnerabilities found by SQIRL, grouped in 6 CVEs. Table 1: A: SQLi payload (highlighted in pink ) escaping its SQL context to cause the database to pause for 1 second. B-D: SQL queries showing 13 semantically different positions where user input can occur. E: current WordPress example of dangerous parameterised query pattern. A: SELECT * FROM tab WHERE val = ' ' AND SLEEP(1) --' B: SELECT input_1 FROM input_2 WHERE input_3 = 'input_4' GROUP BY 'input_5' C: UPDATE input_6 SET (" input_7 " , " input_8 ") D: INSERT INTO input_9 ( input_10 , input_11 ) SET ('input_12', 'input_13')
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e48d062a-094e-4bef-8fbf-5c28d4a47dd5Cited by top-tier papers5
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos et al.USENIX Security 2026 · 7 citations
- APIRL: Deep Reinforcement Learning for REST API FuzzingMyles Foley, Sergio MaffeisAAAI 2025 · 6 citations
- Beyond Rewards in RL for Cyber DefenceElizabeth Bates, Chris Hicks, Vasilios MavroudisICML 2026 · 3 citations
- Zelda: Feedback-driven Closed-box Fuzzing for Identifying Web Application VulnerabilitiesSoyoung Lee, Sunnyeo Park, Yonghwi Kwon, Sooel SonWWW 2026
- Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and AnalysisZiyu Lin, Ziting Wang, Xinfeng Li, Wei Dong et al.USENIX Security 2026
Builds on1
Related papers
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 34 citations
- SQLiFuzz: Uncovering SQL Injection in Any Web ApplicationsI Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih TurkmenFSE 2026
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel et al.S&P 2023
- SquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement LearningCharlie Hou, Mingxun Zhou, Yan Ji, Phil Daian et al.NDSS 2021
- DeepSQLi: deep semantic learning for testing SQL injectionMuyang Liu, Ke Li, Tao ChenISSTA 2020 · 47 citations
