Alotaibi, Fahad and VASILAKIS, VASILEIOS orcid.org/0000-0003-4902-8226 (2023) Toward an SDN-Based Web Application Firewall:Defending against SQL Injection Attacks. Future Internet. 170. ISSN: 1999-5903
Abstract
Web attacks pose a significant threat to enterprises, as attackers often target web applications first. Various solutions have been proposed to mitigate and reduce the severity of these threats, such as web application firewalls (WAFs). On the other hand, software-defined networking (SDN) technology has significantly improved network management and operation by providing centralized control for network administrators. In this work, we investigated the possibility of using SDN to implement a firewall capable of detecting and blocking web attacks. As a proof of concept, we designed and implemented a WAF to detect a known web attack, specifically SQL injection. Our design utilized two detection methods: signatures and regular expressions. The experimental results demonstrate that the SDN controller can successfully function as a WAF and detect SQL injection attacks. Furthermore, we implemented and compared ModSecurity, a traditional WAF, with our proposed SDN-based WAF. The results reveal that our system is more efficient in terms of TCP ACK latency, while ModSecurity exhibits a slightly lower overhead on the controller.
Metadata
| Item Type: | Article |
|---|---|
| Authors/Creators: |
|
| Copyright, Publisher and Additional Information: | © 2023 by the authors |
| Dates: |
|
| Institution: | The University of York |
| Academic Units: | The University of York > Faculty of Sciences (York) > Computer Science (York) |
| Date Deposited: | 11 Mar 2026 16:00 |
| Last Modified: | 12 Mar 2026 00:06 |
| Published Version: | https://doi.org/10.3390/fi15050170 |
| Status: | Published |
| Refereed: | Yes |
| Identification Number: | 10.3390/fi15050170 |
| Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:239015 |
Download
Filename: futureinternet-15-00170-v2.pdf
Description: Toward an SDN-Based Web Application Firewall: Defending against SQL Injection Attacks
Licence: CC-BY 2.5

CORE (COnnecting REpositories)
CORE (COnnecting REpositories)