An Automaton based Approach for forestalling Cross Site Scripting attacks in web application

被引:0
|
作者
Suju, D. Arul [1 ,2 ]
Gandhi, G. Meera [3 ]
机构
[1] Sathyabama Univ, Madras, Tamil Nadu, India
[2] Loyola ICAM Coll Engn & Technol, Dept CSE, Madras, Tamil Nadu, India
[3] Sathyabama Univ, Fac Comp Sci & Engn, Madras, Tamil Nadu, India
来源
2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC) | 2015年
关键词
Automata Theory; OWASP; XSS; Application Layer and Web Security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Application layer attacks are increasing rapidly and are becoming a common threat to Web security. Attackers use many types of vulnerable malicious code to cripple and penetrate a Web site, from low-level attacks to high-level data breaches that expose infrastructure of the web applications. OWSAP 2015 has declared that XSS attacks are amongst the most powerful attacks against web applications. These attacks can be prevented by using techniques like same origin policy, filtering, escaping and other validation approaches. XSS vulnerabilities may lead to effects like denial of service, stealing of cookies, session tokens, and other user sensitive data. We propose a linear based automaton approach called XSS Chaser which prevents web applications from XSS attacks. Our approach performs string analysis to generate vulnerable patterns to prevent XSS. These patterns are generated using onward and backward interpretation. The experimental result shows that our approach provides better response time compared to existing Techniques.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Automated removal of cross site scripting vulnerabilities in web applications
    Shar, Lwin Khin
    Tan, Flee Beng Kuan
    INFORMATION AND SOFTWARE TECHNOLOGY, 2012, 54 (05) : 467 - 478
  • [32] Assessment of Dynamic Open-source Cross-site Scripting Filters for Web Application
    Abu Talib, Nurul Atiqah
    Doh, Kyung-Goo
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (10): : 3750 - 3770
  • [33] A proposed approach for preventing Cross-Site Scripting
    Taha, Twana Assad
    Karabatak, Murat
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 228 - 231
  • [34] Cross Channel Scripting (XCS) Attacks in Web Applications: Detection and Mitigation Approaches
    Madhusudhan, R.
    Shashidhara
    2018 2ND CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2018,
  • [35] Cross Channel Scripting and Code Injection Attacks on Web and Cloud-Based Applications: A Comprehensive Review
    Indushree, M.
    Kaur, Manjit
    Raj, Manish
    Shashidhara, R.
    Lee, Heung-No
    SENSORS, 2022, 22 (05)
  • [36] Browser's Defenses Against Reflected Cross-Site Scripting Attacks
    Mewara, Bhawna
    Bairwa, Sheetal
    Gajrani, Jyoti
    2014 INTERNATIONAL CONFERENCE ON SIGNAL PROPAGATION AND COMPUTER TECHNOLOGY (ICSPCT 2014), 2014, : 662 - 667
  • [37] BLUEPRINT: Robust Prevention of Cross-site Scripting Attacks for Existing Browsers
    Ter Louw, Mike
    Venkatakrishnan, V. N.
    PROCEEDINGS OF THE 2009 30TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2009, : 331 - 346
  • [38] On Security Issues in Web Applications through Cross Site Scripting (XSS)
    Malviya, Vikas K.
    Saurav, Saket
    Gupta, Atul
    2013 20TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2013), VOL 1, 2013, : 583 - 588
  • [39] Content Security Policy (CSP) as countermeasure to Cross Site Scripting (XSS) attacks
    Dolnak, Ivan
    2017 15TH IEEE INTERNATIONAL CONFERENCE ON EMERGING ELEARNING TECHNOLOGIES AND APPLICATIONS (ICETA 2017), 2017, : 99 - 102
  • [40] Machine Learning-Driven Detection of Cross-Site Scripting Attacks
    Alhamyani, Rahmah
    Alshammari, Majid
    INFORMATION, 2024, 15 (07)