首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks
【24h】

XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks

机译:XSS-Dec:缓解跨站点脚本攻击的混合解决方案

获取原文

摘要

Cross-site scripting attacks represent one of the major security threats in today's Web applications. Current approaches to mitigate cross-site scripting vulnerabilities rely on either server-based or client-based defense mechanisms. Although effective for many attacks, server-side protection mechanisms may leave the client vulnerable if the server is not well patched. On the other hand, client-based mechanisms may incur a significant overhead on the client system. In this work, we present a hybrid client-server solution that combines the benefits of both architectures. Our Proxy-based solution leverages the strengths of both anomaly detection and control flow analysis to provide accurate detection. We demonstrate the feasibility and accuracy of our approach through extended testing using real-world cross-site scripting exploits.
机译:跨站点脚本攻击是当今Web应用程序中的主要安全威胁之一。当前缓解跨站点脚本漏洞的方法依赖于基于服务器或基于客户端的防御机制。尽管对许多攻击都有效,但是如果服务器的修补不完善,服务器端保护机制可能会使客户端容易受到攻击。另一方面,基于客户端的机制可能会导致客户端系统的大量开销。在这项工作中,我们提出了一种混合的客户端-服务器解决方案,该解决方案结合了两种体系结构的优点。我们基于代理的解决方案利用异常检测和控制流分析的优势来提供准确的检测。我们通过使用真实的跨站点脚本漏洞进行的扩展测试,证明了我们方法的可行性和准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号