首页> 外文期刊>Arabian Journal for Science and Engineering. Section A, Sciences >XSS-SAFE: A Server-Side Approach to Detect and Mitigate Cross-Site Scripting (XSS) Attacks in JavaScript Code
【24h】

XSS-SAFE: A Server-Side Approach to Detect and Mitigate Cross-Site Scripting (XSS) Attacks in JavaScript Code

机译:XSS-SAFE:一种服务器端方法,用于检测和缓解JavaScript代码中的跨站点脚本(XSS)攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Nowadays, Web applications are considered to be one of the most ubiquitous platforms for providing the information and service release over the World Wide Web, particularly those deployed in health care, banking, ecommerce operations, etc. Boom of social networking sites and modern Web applications that transfer dynamic information to the client-side Web browsers has increased the user-generated and feature-rich HTML content on the Internet. This enhanced HTML content includes a malicious attack vector for Web-related attacks. Cross-site scripting (XSS) attacks are presently themost exploited security problems in modernWeb applications and activated by an attacker to utilize the vulnerabilities of the poorly writtenWeb application source code. Users across all over the popular social networking Web sites are exposed to XSS attacks. These attacks are generally caused by the malicious scripts, which do not validate the user-injected input appropriately and exploit the vulnerabilities in the source code of the Web applications. It results in the loss of confidential information such as stealing of cookies, theft of passwords, and other private credentials. In this paper, we propose a robust framework knownas XSS-SAFE (Cross-Site Scripting SecureWeb Application FramEwork), which is a server-side automated framework for the detection and mitigation of XSS attacks. XSS-SAFE is designed based on the idea of injecting the features of JavaScript and introduced an idea of injecting the sanitization routines in the source code of JavaScript to detect and mitigate the malicious injected XSS attack vectors. We repeatedly inject the feature content, generate rules, and insert sanitization routines for the discovery of XSS attacks. We have evaluated our approach on five realworld JavaServer Pages (JSP) programs. The results indicate that XSS-SAFE detects and mitigates most of the previously known and unknown XSS attacks with minimum false positives, zero false-negative rate, and low runtime overhead.
机译:如今,Web应用程序被认为是广泛的平台之一,为全球网络提供信息和服务释放,特别是部署在医疗保健,银行,电子商务运营等人中的信息。社交网站和现代Web应用程序的繁荣将动态信息传输到客户端Web浏览器在Internet上增加了用户生成的和具有功能丰富的HTML内容。这种增强的HTML内容包括对与Web相关攻击的恶意攻击向量。跨站点脚本(XSS)攻击目前是ModernWeb应用程序中的ThaloSt利用安全问题,并由攻击者激活,以利用Welly Waintweb应用程序源代码的漏洞。所有流行的社交网络网站上的用户都接触到XSS攻击。这些攻击通常由恶意脚本引起,该脚本不会适当地验证用户注入的输入并利用Web应用程序的源代码中的漏洞。它导致丢失机密信息,例如窃取cookie,密码盗窃以及其他私人凭据。在本文中,我们提出了一个强大的框架,姓名为XSS-Safe(跨站点脚本安全网络应用程序框架),它是一种用于检测和缓解XSS攻击的服务器端自动框架。 XSS-Safe是基于注入JavaScript的功能的想法,并介绍了在JavaScript的源代码中注入消毒例程以检测和减轻恶意注入的XSS攻击向量。我们反复注入要素内容,生成规则,并插入消毒例程以发现XSS攻击。我们在五个RealWorld JavaServer页面(JSP)程序上评估了我们的方法。结果表明,XSS-Safe检测和减轻了大多数已知的和未知的XSS攻击,最小误报,零假负速率和低运行时开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号