An Automaton based Approach for forestalling Cross Site Scripting attacks in web application

被引:0
|
作者
Suju, D. Arul [1 ,2 ]
Gandhi, G. Meera [3 ]
机构
[1] Sathyabama Univ, Madras, Tamil Nadu, India
[2] Loyola ICAM Coll Engn & Technol, Dept CSE, Madras, Tamil Nadu, India
[3] Sathyabama Univ, Fac Comp Sci & Engn, Madras, Tamil Nadu, India
来源
2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC) | 2015年
关键词
Automata Theory; OWASP; XSS; Application Layer and Web Security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Application layer attacks are increasing rapidly and are becoming a common threat to Web security. Attackers use many types of vulnerable malicious code to cripple and penetrate a Web site, from low-level attacks to high-level data breaches that expose infrastructure of the web applications. OWSAP 2015 has declared that XSS attacks are amongst the most powerful attacks against web applications. These attacks can be prevented by using techniques like same origin policy, filtering, escaping and other validation approaches. XSS vulnerabilities may lead to effects like denial of service, stealing of cookies, session tokens, and other user sensitive data. We propose a linear based automaton approach called XSS Chaser which prevents web applications from XSS attacks. Our approach performs string analysis to generate vulnerable patterns to prevent XSS. These patterns are generated using onward and backward interpretation. The experimental result shows that our approach provides better response time compared to existing Techniques.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] XSSDS: Server-side Detection of Cross-site Scripting Attacks
    Johns, Martin
    Engelmann, Bjoern
    Posegga, Joachim
    24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 335 - +
  • [42] Cost-effective detection system of cross-site scripting attacks using hybrid learning approach
    Abu Al-Haija, Qasem
    RESULTS IN ENGINEERING, 2023, 19
  • [43] XSStudent: Proposal to Avoid Cross-Site Scripting (XSS) Attacks in Universities
    Escuela Politecnica Nacional, Facultad de Ingenieŕia de Sistemas, Quito, Ecuador
    不详
    Cyber Secur. Netw. Conf., CSNet, 1600, (142-149):
  • [44] Detecting Blind Cross-Site Scripting Attacks Using Machine Learning
    Kaur, Gurpreet
    Malik, Yasir
    Samuel, Hamman
    Jaafar, Fehmi
    2018 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MACHINE LEARNING (SPML 2018), 2018, : 22 - 25
  • [45] XSStudent: Proposal to Avoid Cross-Site Scripting (XSS) Attacks in Universities
    Rodriguez, German
    Torres, Jenny
    Flores, Pamela
    Benavides, Eduardo
    Nunez-Agurto, Daniel
    2019 3RD CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2019,
  • [46] Circe: A Grammar-Based Oracle for Testing Cross-Site Scripting in Web Applications
    Avancini, Andrea
    Ceccato, Mariano
    2013 20TH WORKING CONFERENCE ON REVERSE ENGINEERING (WCRE), 2013, : 262 - 271
  • [47] Developing a Security Model to Protect Websites from Cross-site Scripting Attacks Using Zend Framework Application
    Elhakeem, Yousra Faisal Gad Mahgoup
    Barry, Bazara I. A.
    2013 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRICAL AND ELECTRONICS ENGINEERING (ICCEEE), 2013, : 624 - 629
  • [48] XGBXSS: An Extreme Gradient Boosting Detection Framework for Cross-Site Scripting Attacks Based on Hybrid Feature Selection Approach and Parameters Optimization
    Mokbal, Fawaz Mahiuob Mohammed
    Wang Dan
    Wang Xiaoxi
    Zhao Wenbin
    Fu Lihua
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58
  • [49] Positive Security Model based Server-side Solution for prevention of Cross-site Scripting Attacks
    Maurya, Swati
    2015 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2015,
  • [50] XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks
    Sundareswaran, Smitha
    Squicciarini, Anna Cinzia
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 223 - 238