SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement Learning
Salim Al Wahaibi, Myles Foley, Sergio Maffeis
摘要
Web security scanners are used to discover SQL injection vulnerabilities in deployed web applications. Scanners tend to use static rules to cover the most common injection cases, missing diversity in their payloads, leading to a high volume of requests and false negatives. Moreover, scanners often rely on the presence of error messages or other significant feedback on the target web pages, as a result of additional insecure programming practices by web developers. In this paper we develop SQIRL, a novel approach to detecting SQL injection vulnerabilities based on deep reinforcement learning, using multiple worker agents and grey-box feedback. Each worker intelligently fuzzes the input fields discovered by an automated crawling component. This approach generates a more varied set of payloads than existing scanners, leading to the discovery of more vulnerabilities. Moreover, SQIRL attempts fewer payloads, because they are generated in a targeted fashion. SQIRL finds all vulnerabilities in our microbenchmark for SQL injection, with substantially fewer requests than most of the state-of-the-art scanners compared with. It also significantly outperforms other scanners on a set of 14 production grade web applications, discovering 33 vulnerabilities, with zero false positives. We have responsibly disclosed 22 novel vulnerabilities found by SQIRL, grouped in 6 CVEs. Table 1: A: SQLi payload (highlighted in pink ) escaping its SQL context to cause the database to pause for 1 second. B-D: SQL queries showing 13 semantically different positions where user input can occur. E: current WordPress example of dangerous parameterised query pattern. A: SELECT * FROM tab WHERE val = ' ' AND SLEEP(1) --' B: SELECT input_1 FROM input_2 WHERE input_3 = 'input_4' GROUP BY 'input_5' C: UPDATE input_6 SET (" input_7 " , " input_8 ") D: INSERT INTO input_9 ( input_10 , input_11 ) SET ('input_12', 'input_13')
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos 等USENIX Security 2026 · 被引用 7 次
- APIRL: Deep Reinforcement Learning for REST API FuzzingMyles Foley, Sergio MaffeisAAAI 2025 · 被引用 6 次
- Beyond Rewards in RL for Cyber DefenceElizabeth Bates, Chris Hicks, Vasilios MavroudisICML 2026 · 被引用 3 次
- Zelda: Feedback-driven Closed-box Fuzzing for Identifying Web Application VulnerabilitiesSoyoung Lee, Sunnyeo Park, Yonghwi Kwon, Sooel SonWWW 2026
- Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and AnalysisZiyu Lin, Ziting Wang, Xinfeng Li, Wei Dong 等USENIX Security 2026
它引用的顶会 Paper1
相关 Paper
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 被引用 34 次
- SQLiFuzz: Uncovering SQL Injection in Any Web ApplicationsI Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih TurkmenFSE 2026
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel 等S&P 2023
- SquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement LearningCharlie Hou, Mingxun Zhou, Yan Ji, Phil Daian 等NDSS 2021
- DeepSQLi: deep semantic learning for testing SQL injectionMuyang Liu, Ke Li, Tao ChenISSTA 2020 · 被引用 47 次
