Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review

被引:0
|
作者
Jasleen Kaur
Urvashi Garg
Gourav Bathla
机构
[1] Chandigarh University,
[2] University of Petroleum and Energy Studies,undefined
来源
Artificial Intelligence Review | 2023年 / 56卷
关键词
Web vulnerabilities; Cyber-attacks; Web-security; Machine learning; XSS attack; Deep learning; Neural networks;
D O I
暂无
中图分类号
学科分类号
摘要
With the rising demand for E-commerce, Social Networking websites, it has become essential to develop security protocols over the World Wide Web that can provide security and privacy to Internet users all over the globe. Several traditional encryption techniques and attack detection protocols can secure the data transmitted over public networks. However, hackers can effortlessly exploit them to acquire access to the users’ sensitive information such as user ID, session ID, cookies, passwords, bank account details, contact numbers, private PINs, database information, etc. Researchers have continuously innovated new techniques to build a secure and robust system that cannot be easily hacked and manipulated. Still, there is much scope for novelty to provide security against contemporary techniques used by intruders. The motivation of this survey is to observe the recent developments in Cross-Site Scripting attacks and techniques used by researchers to secure confidential information. Cross-Site Scripting (XSS) has been recognized as one of the top 10 online application security risks by the Open Web Application Security Project (OWASP) for decades. Therefore, dealing with this security flaw in web applications has become essential to avoid further personal and financial damage to Internet users and business organizations. There is a need for an extensive survey of recent XSS attack detection techniques that can provide the right direction to researchers and security professionals. We present a complete overview of recent machine learning and neural network-based XSS attack detection techniques in this paper, covering deep neural networks, decision trees, web-log-based detection models, and many more. This paper also highlights the research gaps that must be addressed while designing attack detection models. Further, challenges researchers face during the development of recent techniques are also discussed. Finally, future directions are provided to reflect on new concepts that can be used in forthcoming research works to improve XSS attack detection techniques.
引用
收藏
页码:12725 / 12769
页数:44
相关论文
共 50 条
  • [21] Detection and Prevention of Cross-site Scripting Attack with Combined Approaches
    Chen, Hsing-Chung
    Nshimiyimana, Aristophane
    Damarjati, Cahya
    Chang, Pi-Hsien
    2021 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2021,
  • [22] Swift Detection of XSS Attacks: Enhancing XSS Attack Detection by Leveraging Hybrid Semantic Embeddings and AI Techniques
    Bakir, Rezan
    Bakir, Halit
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2025, 50 (02) : 1191 - 1207
  • [23] Cross-Site Scripting Guardian: A Static XSS Detector Based on Data Stream Input-Output Association Mining
    Li, Chenghao
    Wang, Yiding
    Miao, Changwei
    Huang, Cheng
    APPLIED SCIENCES-BASEL, 2020, 10 (14):
  • [24] Development of web browser prototype with embedded classification capability for mitigating Cross-Site Scripting attacks
    Malviya, Vikas K.
    Rai, Sawan
    Gupta, Atul
    APPLIED SOFT COMPUTING, 2021, 102
  • [25] Machine Learning for Web Vulnerability Detection: The Case of Cross-Site Request Forgery
    Calzavara, Stefano
    Conti, Mauro
    Focardi, Riccardo
    Rabitti, Alvise
    Tolomei, Gabriele
    IEEE SECURITY & PRIVACY, 2020, 18 (03) : 8 - 16
  • [26] DeepXSS: Cross Site Scripting Detection Based on Deep Learning
    Fang, Yong
    Li, Yang
    Liu, Liang
    Huang, Cheng
    PROCEEDINGS OF 2018 INTERNATIONAL CONFERENCE ON COMPUTING AND ARTIFICIAL INTELLIGENCE (ICCAI 2018), 2018, : 47 - 51
  • [27] Client-side cross-site scripting protection
    Kirda, Engin
    Jovanovic, Nenad
    Kruegel, Christopher
    Vigna, Giovanni
    COMPUTERS & SECURITY, 2009, 28 (07) : 592 - 604
  • [28] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12) : 4008 - 4023
  • [29] Twenty-two years since revealing cross-site scripting attacks: A systematic mapping and a comprehensive survey
    Hannousse, Abdelhakim
    Yahiouche, Salima
    Nait-Hamoud, Mohamed Cherif
    COMPUTER SCIENCE REVIEW, 2024, 52
  • [30] XGBXSS: An Extreme Gradient Boosting Detection Framework for Cross-Site Scripting Attacks Based on Hybrid Feature Selection Approach and Parameters Optimization
    Mokbal, Fawaz Mahiuob Mohammed
    Wang Dan
    Wang Xiaoxi
    Zhao Wenbin
    Fu Lihua
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58