首页> 外文期刊>Computer networks >Cross-site scripting (XSS) attacks and mitigation: A survey
【24h】

Cross-site scripting (XSS) attacks and mitigation: A survey

机译:跨站点脚本(XSS)攻击和缓解:一项调查

获取原文
获取原文并翻译 | 示例

摘要

The results of the Cisco 2018 Annual Security Report show that all analyzed web applications have at least one vulnerability. It also shows that web attacks are becoming more frequent, specific and sophisticated. According to this report, 40% of all attack attempts lead to a method known as Cross-Site Scripting (XSS), which was the most widely used technique. According to the OWASP Top 10 - 2017 security risk, this type of attack is ranked No. 7, and it is noted that XSS is present in approximately two thirds of all web applications.This attack occurs when a malicious user uses a web application to execute or send malicious code on another user's computer. Also, Cross Site Scripting is a type of cyber attack by which vulnerabilities are searched in a web application to introduce a harmful script. This implies that user information can be affected by stealing cookies, phishing, or attacking a company's entire network.In this context, we have analyzed a total of 67 documents to collect information of the tools and methods that the scientific community has used to detect and mitigate these type of attack. It has been hypothesized that the trend in the proposal of traditional methods to mitigate XSS attacks is greater than the proposals that use some artificial intelligence technique. Our results show that the trend is increasing in the proposals that analyze the content of web pages (13.20%), as well as those that serve as a toolkit for web browsers (16.98%). Also, we have found that there is a low tendency in the use of artificial intelligence techniques to detect or mitigate this attack, using Web Classifiers (9.43%). (C) 2019 Elsevier B.V. All rights reserved.
机译:思科2018年度安全报告的结果显示,所有分析的Web应用程序均至少具有一个漏洞。它还表明,Web攻击正变得越来越频繁,具体和复杂。根据此报告,所有攻击尝试中有40%导致一种称为跨站点脚本(XSS)的方法,该方法是使用最广泛的技术。根据OWASP 2017年排名前10位的安全风险,此类攻击排名第7位,并且值得注意的是,所有Web应用程序中约有三分之二存在XSS。这种攻击是在恶意用户使用Web应用程序进行攻击时发生的在其他用户的计算机上执行或发送恶意代码。同样,跨站点脚本是一种网络攻击,通过它可以在Web应用程序中搜索漏洞以引入有害脚本。这意味着用户信息可能会受到窃取Cookie,网络钓鱼或攻击公司整个网络的影响。在这种情况下,我们共分析了67个文档,以收集科学界用来检测和检测工具和方法的信息。减轻这类攻击。已经假设,减轻XSS攻击的传统方法的提议的趋势比使用某种人工智能技术的提议的趋势更大。我们的结果表明,分析网页内容的提案(13.20%)以及用作Web浏览器工具包的提案(16.98%)的趋势正在增加。此外,我们发现使用Web分类器(9.43%)来使用人工智能技术检测或减轻这种攻击的趋势很小。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号