首页> 外文会议>IEEE International Conference on Electro/Information Technology >A Google Chromium Browser Extension for Detecting XSS Attack in HTML5 Based Websites
【24h】

A Google Chromium Browser Extension for Detecting XSS Attack in HTML5 Based Websites

机译:Google Chromium浏览器扩展程序,用于检测基于HTML5的网站中的XSS攻击

获取原文

摘要

The advent of HTML 5 revives the life of cross-site scripting attack (XSS) in the web. Cross Document Messaging, Local Storage, Attribute Abuse, Input Validation, Inline Multimedia and SVG emerge as likely targets for serious threats. Introduction of various new tags and attributes can be potentially manipulated to exploit the data on a dynamic website. The XSS attack manages to retain a spot in all the OWASP Top 10 security risks released over the past decade and placed in the seventh spot in OWASP Top 10 of 2017. It is known that XSS attempts to execute scripts with untrusted data without proper validation between websites. XSS executes scripts in the victim's browser which can hijack user sessions, deface websites, or redirect the user to the malicious site. This paper focuses on the development of a browser extension for the popular Google Chromium browser that keeps track of various attack vectors. These vectors primarily include tags and attributes of HTML 5 that may be used maliciously. The developed plugin alerts users whenever a possibility of XSS attack is discovered when a user accesses a particular website.
机译:HTML 5的出现使网络中的跨站点脚本攻击(XSS)焕发了生命。跨文档消息传递,本地存储,属性滥用,输入验证,嵌入式多媒体和SVG成为严重威胁的可能目标。可以潜在地操纵各种新标签和属性的引入,以利用动态网站上的数据。 XSS攻击设法在过去十年中发布的所有OWASP Top 10安全风险中占据一席之地,并在2017年OWASP Top 10中排名第七。网站。 XSS在受害人的浏览器中执行脚本,该脚本可能劫持用户会话,破坏网站或将用户重定向到恶意站点。本文重点研究流行的Google Chromium浏览器的浏览器扩展的开发,该扩展可跟踪各种攻击媒介。这些向量主要包括可能被恶意使用的HTML 5的标记和属性。当用户访问特定网站时,一旦发现XSS攻击的可能性,开发的插件就会向用户发出警报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号