首页> 外文会议>International Conference on Anti-Cyber Crimes >Payload recognition and detection of Cross Site Scripting attack
【24h】

Payload recognition and detection of Cross Site Scripting attack

机译:有效载荷识别和跨站点脚本攻击的检测

获取原文
获取外文期刊封面目录资料

摘要

Web Application becomes the leading solution for the utilization of systems that need access globally, distributed, cost-effective, as well as the diversity of the content that can run on this technology. At the same time web application security have always been a major issue that must be considered due to the fact that 60% of Internet attacks targeting web application platform. One of the biggest impacts on this technology is Cross Site Scripting (XSS) attack, the most frequently occurred and are always in the TOP 10 list of Open Web Application Security Project (OWASP). Vulnerabilities in this attack occur in the absence of checking, testing, and the attention about secure coding practices. There are several alternatives to prevent the attacks that associated with this threat. Network Intrusion Detection System can be used as one solution to prevent the influence of XSS Attack. This paper investigates the XSS attack recognition and detection using regular expression pattern matching and a preprocessing method. Experiments are conducted on a testbed with the aim to reveal the behaviour of the attack.
机译:Web应用程序成为利用全局访问的系统的领先解决方案,分布式,经济效益以及可以在此技术上运行的内容的多样性。与此同时,Web应用程序安全始终是必须考虑的主要问题,这是由于60%的互联网攻击定位Web应用程序平台。对该技术的最大影响之一是跨站点脚本(XSS)攻击,最常发生的,并且始终位于开放式Web应用程序安全项目(OWASP)的前10个列表中。在没有检查,测试和关注安全编码实践的情况下,此次攻击中发生的漏洞发生。有几种替代方案可以防止与这种威胁相关的攻击。网络入侵检测系统可用作防止XSS攻击影响的一种解决方案。本文研究了使用正则表达式匹配和预处理方法的XSS攻击识别和检测。实验在测试平台上进行,目的是揭示攻击的行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号