首页> 外文会议>International Conference on Advanced Computing >An automaton based approach for forestalling cross site scripting attacks in web application
【24h】

An automaton based approach for forestalling cross site scripting attacks in web application

机译:一种基于自动机的方法,可防止Web应用程序中的跨站点脚本攻击

获取原文

摘要

Application layer attacks are increasing rapidly and are becoming a common threat to Web security. Attackers use many types of vulnerable malicious code to cripple and penetrate a Web site, from low-level attacks to high-level data breaches that expose infrastructure of the web applications. OWSAP 2015 has declared that XSS attacks are amongst the most powerful attacks against web applications. These attacks can be prevented by using techniques like same origin policy, filtering, escaping and other validation approaches. XSS vulnerabilities may lead to effects like denial of service, stealing of cookies, session tokens, and other user sensitive data. We propose a linear based automaton approach called XSS Chaser which prevents web applications from XSS attacks. Our approach performs string analysis to generate vulnerable patterns to prevent XSS. These patterns are generated using onward and backward interpretation. The experimental result shows that our approach provides better response time compared to existing Techniques.
机译:应用层攻击正在迅速增加,并已成为对Web安全的普遍威胁。攻击者使用多种类型的易受攻击的恶意代码来破坏和渗透网站,从低级攻击到暴露Web应用程序基础结构的高级别数据泄露。 OWSAP 2015宣布XSS攻击是针对Web应用程序的最强大的攻击之一。可以通过使用诸如相同来源策略,过滤,转义和其他验证方法之类的技术来防止这些攻击。 XSS漏洞可能导致拒绝服务,窃取Cookie,会话令牌和其他用户敏感数据之类的后果。我们提出了一种基于线性的自动机方法,称为XSS Chaser,它可以防止Web应用程序受到XSS攻击。我们的方法执行字符串分析,以生成易受攻击的模式来防止XSS。这些模式是使用向前和向后解释生成的。实验结果表明,与现有技术相比,我们的方法可提供更好的响应时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号