CONCLUSION AND FUTUREWORK In this paper, we presented a novel technique against SQLIAs. Our approach is based on the intuition that the web-application code implicitly contains a policy that allows for distinguishing legitimate and malicious queries.