MACHINE LEARNING DETECTION OF DATABASE INJECTION ATTACKS

Patent №

US 11,030,203

Granted

2021-06-08

Filed 2018

Owner

SAP SE

Lab

AI components

3

ml · kr · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

16140558

Techniques and solutions are described for detecting malicious database activity, such as SQL injection attempts. A first machine learning classifier can be trained by comparing processed and unprocessed user input, where a difference between the two can indicate suspicious or malicious activity. The trained classifier can be used to analyze user input before query execution. A second machine learning classifier is trained with a data set that includes call stack information for an application requesting execution of a dynamic query and query statistics associated with processing of the query at the database. The query of the application can be correlated with a corresponding database query by hashing the application query and the database query and comparing the hash values, where matching hash value indicate a common query. The trained classifier can monitor execution of future queries to identify queries having anomalous patterns, which may indicate malicious or suspicious activity.

Machine learningKnowledge representationAI hardwareH04L 63/1466G06F 16/21G06F 16/2255G06F 16/2462G06F 18/214G06N 20/00

AI classification

AI hardware1.00
Machine learning0.99
Knowledge representation0.77
Natural language0.35
Speech0.00
Evolutionary computation0.00
Planning0.00
Vision0.00

Ownership

SAP SE

assignment · 469820715

Assignors

KLEIN, UDO

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC