【24h】

A Dynamic Detection Technique for XSS Vulnerabilities

机译:XSS漏洞的动态检测技术

获取原文

摘要

This paper studies the principle of vulnerability generation and mechanism of cross-site scripting attack, designs a dynamic cross-site scripting vulnerabilities detection technique based on existing theories of black box vulnerabilities detection. The dynamic detection process contains five steps: crawler, feature construct, attacks simulation, results detection and report generation. Crawling strategy in crawler module and constructing algorithm in feature construct module are key points of this detection process. Finally, according to the detection technique proposed in this paper, a detection tool is accomplished in Linux using python language to detect web applications. Experiments were launched to verify the results and compare with the test results of other existing tools, analyze the usability, advantages and disadvantages of the detection method above, confirm the feasibility of applying dynamic detection technique to cross-site scripting vulnerabilities detection.
机译:本文研究了漏洞产生的原理和跨站脚本攻击的机制,在现有黑盒漏洞检测理论的基础上,设计了一种动态的跨站脚本漏洞检测技术。动态检测过程包含五个步骤:搜寻器,功能构建,攻击模拟,结果检测和报告生成。爬虫模块中的爬虫策略和特征构造模块中的构造算法是该检测过程的关键。最后,根据本文提出的检测技术,使用python语言在Linux中完成了一个检测工具来检测Web应用程序。开展了实验以验证结果,并与其他现有工具的测试结果进行比较,分析上述检测方法的可用性,优缺点,确认将动态检测技术应用于跨站点脚本漏洞检测的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号