首页> 外文会议>International Conference on Computational Data and Social Networks >XSSPro: XSS Attack Detection Proxy to Defend Social Networking Platforms
【24h】

XSSPro: XSS Attack Detection Proxy to Defend Social Networking Platforms

机译:XSSPRO:XSS攻击检测代理捍卫社交网络平台

获取原文
获取外文期刊封面目录资料

摘要

Social Platforms transpired as the fascinating attack surface to explode multitude of cyber-attacks as it facilitates sharing of personal and professional information. XSS vulnerability exists approximately in 80% of the social platforms. Hence, this paper presents an approach, XSSPro, to defend social networking platforms against XSS attacks. XSSPro operates through isolating the JavaScript code in the external file and performs decoding operation. The context of each injected JS code is identified and then similar scripts are grouped together to optimize the performance of XSSPro. Finally, extracted scripts are matched against the XSS attack vector repository to detect XSS attack. If matched then it is refined by using XSS APIs, otherwise, the response is XSS free and sent to the user. Experimental results revealed that XSSPro achieved an accuracy of 0.99 and is effective against thwarting XSS attack triggered using new features of the built-in code language with low false alarm rate.
机译:作为迷人的攻击面的社交平台,促进众多网络攻击,促进分享个人和专业信息。 XSS漏洞大约存在于80%的社交平台。因此,本文介绍了一种方法,XSSPRO,以防止XSS攻击的社交网络平台。 XSSPRO通过在外部文件中隔离JavaScript代码并执行解码操作来操作。识别每个注入的JS代码的上下文,然后将类似的脚本分组为优化XSSPro的性能。最后,提取的脚本与XSS攻击向量存储库匹配以检测XSS攻击。如果匹配,则通过使用XSS API来改进它,否则,响应是XSS,并发送给用户。实验结果表明,XSSPRO实现了0.99的精度,并且对使用具有低误报率的内置代码语言的新功能触发触发的XSS攻击是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号