An Automaton based Approach for forestalling Cross Site Scripting attacks in web application

被引:0
|
作者
Suju, D. Arul [1 ,2 ]
Gandhi, G. Meera [3 ]
机构
[1] Sathyabama Univ, Madras, Tamil Nadu, India
[2] Loyola ICAM Coll Engn & Technol, Dept CSE, Madras, Tamil Nadu, India
[3] Sathyabama Univ, Fac Comp Sci & Engn, Madras, Tamil Nadu, India
来源
2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC) | 2015年
关键词
Automata Theory; OWASP; XSS; Application Layer and Web Security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Application layer attacks are increasing rapidly and are becoming a common threat to Web security. Attackers use many types of vulnerable malicious code to cripple and penetrate a Web site, from low-level attacks to high-level data breaches that expose infrastructure of the web applications. OWSAP 2015 has declared that XSS attacks are amongst the most powerful attacks against web applications. These attacks can be prevented by using techniques like same origin policy, filtering, escaping and other validation approaches. XSS vulnerabilities may lead to effects like denial of service, stealing of cookies, session tokens, and other user sensitive data. We propose a linear based automaton approach called XSS Chaser which prevents web applications from XSS attacks. Our approach performs string analysis to generate vulnerable patterns to prevent XSS. These patterns are generated using onward and backward interpretation. The experimental result shows that our approach provides better response time compared to existing Techniques.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Impact Analysis of Preventing Cross Site Scripting and SQL Injection Attacks on Web Application
    Pandurang, Rathod Mahesh
    Karia, Deepak C.
    2015 IEEE BOMBAY SECTION SYMPOSIUM (IBSS), 2015,
  • [2] Detection of Web Cross-Site Scripting (XSS) Attacks
    Alsaffar, Mohammad
    Aljaloud, Saud
    Mohammed, Badiea Abdulkarem
    Al-Mekhlafi, Zeyad Ghaleb
    Almurayziq, Tariq S.
    Alshammari, Gharbi
    Alshammari, Abdullah
    ELECTRONICS, 2022, 11 (14)
  • [3] Cross Site Scripting: Removing Approaches in Web Application
    Marashdih, Abdalla Wasef
    Zaaba, Zarul Fitri
    4TH INFORMATION SYSTEMS INTERNATIONAL CONFERENCE (ISICO 2017), 2017, 124 : 647 - 655
  • [4] Cross Site Scripting: Detection Approaches in Web Application
    Marashdih, Abdalla Wasef
    Zaaba, Zarul Fitri
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (10) : 155 - 160
  • [5] Prevention of cross-site scripting attacks on current web applications
    Garcia-Alfaro, Joaquin
    Navarro-Arribas, Guillermo
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: COOPIS, DOA, ODBASE, GADA, AND IS, PT 2, PROCEEDINGS, 2007, 4804 : 1770 - +
  • [6] Cross Site Scripting: Investigations in PHP Web Application
    Marashdih, Abdalla Wasef
    Zaaba, Zarul Fitri
    Suwais, Khaled
    2018 INTERNATIONAL CONFERENCE ON PROMISING ELECTRONIC TECHNOLOGIES (ICPET 2018), 2018, : 25 - 30
  • [7] A Mapping-based Podel for Preventing Cross Site Scripting and SQL Injection Attacks on Web Application and its Impact Analysis
    Pandurang, Rathod Mahesh
    Karia, Deepak C.
    2015 1ST INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING TECHNOLOGIES (NGCT), 2015, : 414 - 418
  • [8] A Novel Approach for Detection of SQL Injection and Cross Site Scripting Attacks
    Sonewar, Piyush A.
    Mhetre, Nalini A.
    2015 INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING (ICPC), 2015,
  • [9] Improved cross site scripting filter for input validation against attacks in web services
    Uma, Elangovan
    Kannan, Arputharaj
    KUWAIT JOURNAL OF SCIENCE, 2014, 41 (02) : 175 - 203
  • [10] The Web applications Cross Site Scripting Attacks and Preventions Using Machin learning Technique
    Alyasin, Eman Ibrahim
    Ata, Oguz
    Ozturk, Bilal A.
    INTERNATIONAL JOURNAL OF MULTIPHYSICS, 2024, 18 (03) : 1116 - 1120