Skip to content
Review Open access

Current trends and research gaps in SQL injection simulation and mitigation for IaaS: A systematic review

Jul 2026 · Multidisciplinary Reviews · Vol 10, pp. 2027043 · 0 citations · 44 references

TL;DR

It is concluded that future research must pivot toward adaptive, real-time detection frameworks and more realistic cloud simulation models, ultimately providing a roadmap for more resilient cybersecurity infrastructures.

Abstract

The rapid migration of enterprise operations to cloud environments has significantly escalated the risk of SQL injection (SQLi) attacks, necessitating more robust defence mechanisms for web applications. This study aims to provide a comprehensive evaluation of the current SQLi landscape, focusing on attack typologies, detection methodologies, and mitigation efficacy. Using the PRISMA framework, a systematic literature review was conducted on 38 peer-reviewed studies published between 2021 and 2025, indexed in the Scopus and Web of Science databases. The analysis reveals that 60% of research focuses on general SQLi threats, while specialized subtypes remain under-investigated, with 29% addressing blind/ordered injections and only 3% targeting specific in-band or out-of-band vulnerabilities. Regarding detection, the field is dominated by static analysis (32%), followed by deep learning (21%) and hybrid approaches (21%), whereas dynamic and rule-based methods comprise only 10% and 3%, respectively. For mitigation, deep learning (48%) and machine learning (37%) emerge as the primary defences, with reinforcement learning and algorithmic solutions each contributing 5%. The results demonstrate that while current models excel in simulated environments, there is a critical gap in validating traffic within live Infrastructure-as-a-Service (IaaS) platforms. Furthermore, the findings highlight a lack of resilience against adversarial attacks and imbalanced datasets. This study concludes that future research must pivot toward adaptive, real-time detection frameworks and more realistic cloud simulation models. These insights are vital for developers and security architects aiming to safeguard cloud-native applications against evolving injection techniques, ultimately providing a roadmap for more resilient cybersecurity infrastructures.

Read PDF

Similar papers

Review Open access Aug 2026

Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges

This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics, and reveals a definitive and strategic maturation in adversarial approach.

Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas et al. · 0 citations

TOP 10

The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.

Nuriddinova Dilnura, Samarov Sherzod, Hamrayevich · 0 citations
Open access Aug 2026

Security challenges in serverless architectures: Vulnerabilities and penetration testing approaches for AWS Lambda and Google Cloud Functions

This study examines the evolving security landscape of serverless computing, specifically focusing on AWS Lambda and Google Cloud Functions. While serverless architectures offer significant scalability and cost advantages, their event-driven nature introduces unique vulnerabilities that traditional infrastructure-based...

Norsyazwani Mohd Puad, Paiwand Hadi Hama Saeed, Braw Araz Mohammed et al. · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Open access Sep 2026

From Open Redirect to JavaScript Execution via CVE-2024-4367

This case study presents a forensically documented analysis of a multi-stage security incident involving CVE-2024-4367, an arbitrary JavaScript execution vulnerability in PDF.js. The incident occurred on one PKP Open Journal Systems (OJS) deployment. The observed chain involved an open redirect in the host platform's s...

Muhammad Hendra Sunarya, M. N. D. Nugroho, Reja Revaldy F et al. · 0 citations
Review Open access Aug 2026

Application-Layer DDoS Attacks and Defences: A Taxonomy, Comparative Evaluation Framework, and Research Directions

Distributed Denial of Service (DDoS) attacks have gained popularity among cybercriminals as a favoured method of disruption. Application layer DDoS attacks are particularly intricate, as they overload web servers with re-quests, rendering them inaccessible to legitimate users and causing availability issues. These atta...

Aditya Arsh, Priyanka Biswas, Nirmalya Kar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.