Detection of Web Cross-Site Scripting (XSS) Attacks

被引:4
作者
Alsaffar, Mohammad [1 ]
Aljaloud, Saud [1 ]
Mohammed, Badiea Abdulkarem [2 ,3 ]
Al-Mekhlafi, Zeyad Ghaleb [1 ,4 ]
Almurayziq, Tariq S. [1 ]
Alshammari, Gharbi [1 ]
Alshammari, Abdullah [1 ]
机构
[1] Univ Hail, Coll Comp Sci & Engn, Dept Informat & Comp Sci, Hail 81481, Saudi Arabia
[2] Univ Hail, Coll Comp Sci & Engn, Dept Comp Engn, Hail 81481, Saudi Arabia
[3] Hodeidah Univ, Coll Comp Sci & Engn, POB 3114, Al Hudaydah, Yemen
[4] Aden Community Coll, Aden 967, Yemen
关键词
XSS vulnerabilities; XSS; web security; web attacks;
D O I
10.3390/electronics11142212
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Most applications looking for XSS vulnerabilities have a variety of weaknesses related to the nature of constructing internet applications. Existing XSS vulnerability packages solely scan public net resources, which negatively influences the safety of internet resources. Threats may be in non-public sections of internet resources that can only be accessed by approved users. The aim of this work is to improve available internet functions for preventing XSS assaults by creating a programme that detects XSS vulnerabilities by completely mapping internet applications. The innovation of this work lies in its use of environment-friendly algorithms for locating extraordinary XSS vulnerabilities in addition to encompassing pre-approved XSS vulnerability scanning in examined internet functions to generate a complete internet resource map. Using the developed programme to discover XSS vulnerabilities increases the effectiveness of internet utility protection. This programme also simplifies the use of internet applications. Even customers unfamiliar with the fundamentals of internet security can use this programme due to its capability to generate a document with suggestions for rectifying detected XSS vulnerabilities.
引用
收藏
页数:13
相关论文
共 21 条
  • [11] Effective Filter for Common Injection Attacks in Online Web Applications
    Ibarra-Fiallos, Santiago
    Higuera, Javier Bermejo
    Intriago-Pazmino, Monserrate
    Higuera, Juan Ramon Bermejo
    Montalvo, Juan Antonio Sicilia
    Cubo, Javier
    [J]. IEEE ACCESS, 2021, 9 (09): : 10378 - 10391
  • [12] Cross Channel Scripting and Code Injection Attacks on Web and Cloud-Based Applications: A Comprehensive Review
    Indushree, M.
    Kaur, Manjit
    Raj, Manish
    Shashidhara, R.
    Lee, Heung-No
    [J]. SENSORS, 2022, 22 (05)
  • [13] An ensemble classification-based approach to detect attack level of SQL injections
    Kasim, Omer
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 59
  • [14] Mohammed B.A., 2021, INT C ADV CYBER SECU, P379
  • [15] Accuracy of Phishing Websites Detection Algorithms by Using Three Ranking Techniques
    Mohammed, Badiea Abdulkarem
    Al-Mekhlafi, Zeyad Ghaleb
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2022, 22 (02): : 272 - 282
  • [16] Rao Ganga Rama Koteswara, 2021, Advances in Smart System Technologies. Select Proceedings of ICFSST 2019. Advances in Intelligent Systems and Computing (AISC 1163), P71, DOI 10.1007/978-981-15-5029-4_7
  • [17] Revenkov P.V., 2021, RES BRUTE FORCE BLAC
  • [18] Cross-site scripting (XSS) attacks and mitigation: A survey
    Rodriguez, German E.
    Torres, Jenny G.
    Flores, Pamela
    Benavides, Diego E.
    [J]. COMPUTER NETWORKS, 2020, 166
  • [19] Sarjitus O., 2019, INT J SCI RES COMPUT, V5
  • [20] Wibowo R, 2021, INDONESIAN J INFORM, V3, P149, DOI [10.24002/ijis.v3i2.4192, DOI 10.24002/IJIS.V3I2.4192]