首页> 外文会议>Detection of Intrusions and Malware, and Vulnerability Assessment >XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks
【24h】

XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks

机译:XSS-GUARD:精确动态阻止跨站点脚本攻击

获取原文
获取原文并翻译 | 示例

摘要

This paper focuses on defense mechanisms for cross-site scripting attacks, the top threat on web applications today. It is believed that input validation (or filtering) can effectively prevent XSS attacks on the server side. In this paper, we discuss several recent real-world XSS attacks and analyze the reasons for the failure of filtering mechanisms in defending these attacks. We conclude that while filtering is useful as a first level of defense against XSS attacks, it is ineffective in preventing several instances of attack, especially when user input includes content-rich HTML. We then propose XSS-Guard, a new framework that is designed to be a prevention mechanism against XSS attacks on the server side. XSS-GUARD works by dynamically learning the set of scripts that a web application intends to create for any HTML request. Our approach also includes a robust mechanism for identifying scripts at the server side and removes any script in the output that is not intended by the web application. We discuss extensive experimental results that demonstrate the resilience of XSS-Guard in preventing a number of real-world XSS exploits.
机译:本文关注于跨站点脚本攻击的防御机制,这是当今Web应用程序面临的最大威胁。可以相信,输入验证(或过滤)可以有效地防止服务器端的XSS攻击。在本文中,我们讨论了几种最新的实际XSS攻击,并分析了防御这些攻击的过滤机制失败的原因。我们得出的结论是,尽管过滤作为抵御XSS攻击的第一级防护很有用,但它在阻止多种攻击实例方面效果不佳,尤其是当用户输入包含内容丰富的HTML时。然后,我们提出XSS-Guard,这是一个旨在防止服务器端XSS攻击的机制的新框架。 XSS-GUARD通过动态学习Web应用程序打算为任何HTML请求创建的脚本集来工作。我们的方法还包括用于在服务器端标识脚本的健壮机制,并删除Web应用程序不需要的输出中的任何脚本。我们讨论了广泛的实验结果,这些结果证明了XSS-Guard在防止大量实际XSS攻击中的弹性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号