首页> 外文期刊>Indian Journal of Science and Technology >Removing Cross-Site Scripting Vulnerabilities from Web Applications using the OWASP ESAPI Security Guidelines
【24h】

Removing Cross-Site Scripting Vulnerabilities from Web Applications using the OWASP ESAPI Security Guidelines

机译:使用OWASP ESAPI安全准则从Web应用程序中删除跨站点脚本漏洞

获取原文
           

摘要

Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including cross-site scripting, have caused damages for both web site owners and users. Cross-site scripting vulnerabilities are easy to exploit but difficult to eliminate. Most solutions provided only focus on preventing attacks or detecting the vulnerabilities. Very few research works have addressed eliminating these vulnerabilities from the web applications source codes. In this paper, we propose an approach to remove cross-site scripting vulnerabilities from the source code before an application is deployed. We make use of the OWASP cross-site scripting prevention rules as guideline in our approach. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluation results have indicated promising results.
机译:许多Web应用程序中都存在软件安全漏洞,并每天导致许多成功的攻击。这些攻击,包括跨站点脚本编写,已经对网站所有者和用户造成了损害。跨站点脚本漏洞很容易利用,但很难消除。提供的大多数解决方案仅专注于防止攻击或检测漏洞。很少有研究工作致力于消除Web应用程序源代码中的这些漏洞。在本文中,我们提出了一种在部署应用程序之前从源代码中消除跨站点脚本漏洞的方法。在我们的方法中,我们以OWASP跨站点脚本防护规则为准则。到目前为止,尽管可以在其他编程语言中稍加修改即可实现,但该提议的方法仅在基于Java的Web应用程序上实现和验证。初步评估结果表明前景乐观。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号