...
首页> 外文期刊>Journal of computer networks and communications >Detecting Cross-Site Scripting in Web Applications Using Fuzzy Inference System
【24h】

Detecting Cross-Site Scripting in Web Applications Using Fuzzy Inference System

机译:使用模糊推理系统检测Web应用程序中的跨站点脚本

获取原文
           

摘要

With improvement in computing and technological advancements, web-based applications are now ubiquitous on the Internet. However, these web applications are becoming prone to vulnerabilities which have led to theft of confidential information, data loss, and denial of data access in the course of information transmission. Cross-site scripting (XSS) is a form of web security attack which involves the injection of malicious codes into web applications from untrusted sources. Interestingly, recent research studies on the web application security centre focus on attack prevention and mechanisms for secure coding; recent methods for those attacks do not only generate high false positives but also have little considerations for the users who oftentimes are the victims of malicious attacks. Motivated by this problem, this paper describes an “intelligent” tool for detecting cross-site scripting flaws in web applications. This paper describes the method implemented based on fuzzy logic to detect classic XSS weaknesses and to provide some results on experimentations. Our detection framework recorded 15% improvement in accuracy and 0.01% reduction in the false-positive rate which is considerably lower than that found in the existing work by Koli et al. Our approach also serves as a decision-making tool for the users.
机译:随着计算和技术进步的改进,基于Web的应用程序现在在Internet上无处不在。但是,这些Web应用程序变得容易产生漏洞,这些漏洞已导致在信息传输过程中盗窃机密信息,丢失数据以及拒绝数据访问。跨站点脚本(XSS)是Web安全攻击的一种形式,涉及从不受信任的来源向Web应用程序注入恶意代码。有趣的是,最近对Web应用程序安全中心的研究集中在攻击防范和安全编码机制上。针对这些攻击的最新方法不仅会产生高误报率,而且对于经常是恶意攻击的受害者的用户也没有多大考虑。受此问题的影响,本文介绍了一种用于检测Web应用程序中跨站点脚本缺陷的“智能”工具。本文介绍了一种基于模糊逻辑的方法,用于检测经典XSS弱点并提供一些实验结果。我们的检测框架记录了15%的准确度提高和0.01%的假阳性率降低,这大大低于Koli等人在现有工作中发现的错误率。我们的方法还可以为用户提供决策工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号