Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review

被引:0
作者
Jasleen Kaur
Urvashi Garg
Gourav Bathla
机构
[1] Chandigarh University,
[2] University of Petroleum and Energy Studies,undefined
来源
Artificial Intelligence Review | 2023年 / 56卷
关键词
Web vulnerabilities; Cyber-attacks; Web-security; Machine learning; XSS attack; Deep learning; Neural networks;
D O I
暂无
中图分类号
学科分类号
摘要
With the rising demand for E-commerce, Social Networking websites, it has become essential to develop security protocols over the World Wide Web that can provide security and privacy to Internet users all over the globe. Several traditional encryption techniques and attack detection protocols can secure the data transmitted over public networks. However, hackers can effortlessly exploit them to acquire access to the users’ sensitive information such as user ID, session ID, cookies, passwords, bank account details, contact numbers, private PINs, database information, etc. Researchers have continuously innovated new techniques to build a secure and robust system that cannot be easily hacked and manipulated. Still, there is much scope for novelty to provide security against contemporary techniques used by intruders. The motivation of this survey is to observe the recent developments in Cross-Site Scripting attacks and techniques used by researchers to secure confidential information. Cross-Site Scripting (XSS) has been recognized as one of the top 10 online application security risks by the Open Web Application Security Project (OWASP) for decades. Therefore, dealing with this security flaw in web applications has become essential to avoid further personal and financial damage to Internet users and business organizations. There is a need for an extensive survey of recent XSS attack detection techniques that can provide the right direction to researchers and security professionals. We present a complete overview of recent machine learning and neural network-based XSS attack detection techniques in this paper, covering deep neural networks, decision trees, web-log-based detection models, and many more. This paper also highlights the research gaps that must be addressed while designing attack detection models. Further, challenges researchers face during the development of recent techniques are also discussed. Finally, future directions are provided to reflect on new concepts that can be used in forthcoming research works to improve XSS attack detection techniques.
引用
收藏
页码:12725 / 12769
页数:44
相关论文
共 50 条
  • [31] Web Application Attacks Detection Using Machine Learning Techniques
    Betarte, Gustavo
    Martinez, Rodrigo
    Pardo, Alvaro
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2018, : 1065 - 1072
  • [32] IoT Attacks Detection Using Supervised Machine Learning Techniques
    Aljabri, Malak
    Shaahid, Afrah
    Alnasser, Fatima
    Saleh, Asalah
    Alomari, Dorieh
    Aboulnour, Menna
    Al-Eidarous, Walla
    Althubaity, Areej
    HighTech and Innovation Journal, 2024, 5 (03): : 534 - 550
  • [33] Research and implementation of Detecting Cross-Site Scripting Vulnerabilities Based on Crawler
    Zhen Wu
    Min Wang
    Sheng Wu
    PROCEEDINGS OF 2010 ASIA-PACIFIC YOUTH CONFERENCE ON COMMUNICATION, VOLS 1 AND 2, 2010, : 292 - +
  • [34] Detecting DOM-Sourced Cross-Site Scripting in Browser Extensions
    Pan, Jinkun
    Mao, Xiaoguang
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2017, : 24 - 34
  • [35] Cancer detection and segmentation using machine learning and deep learning techniques: a review
    Rai, Hari Mohan
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (09) : 27001 - 27035
  • [36] Cancer detection and segmentation using machine learning and deep learning techniques: a review
    Hari Mohan Rai
    Multimedia Tools and Applications, 2024, 83 : 27001 - 27035
  • [37] A New Cross-site Scripting Detection Mechanism Integrated with HTML']HTML5 and CORS Properties by Using Browser Extensions
    Wang, Chih-Hung
    Zhou, Yi-Shauin
    2016 INTERNATIONAL COMPUTER SYMPOSIUM (ICS), 2016, : 264 - 269
  • [38] Machine and Deep Learning-based XSS Detection Approaches: A Systematic Literature Review
    Thajeel, Isam Kareem
    Samsudin, Khairulmizam
    Hashim, Shaiful Jahari
    Hashim, Fazirulhisyam
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (07)
  • [39] Review on intrusion detection using feature selection with machine learning techniques
    Kalimuthan, C.
    Renjit, J. Arokia
    MATERIALS TODAY-PROCEEDINGS, 2020, 33 : 3794 - 3802
  • [40] UniEmbed: A Novel Approach to Detect XSS and SQL Injection Attacks Leveraging Multiple Feature Fusion with Machine Learning Techniques
    Bakir, Rezan
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2025,