首页> 外文期刊>ETRI journal >Taint Inference for Cross-Site Scripting in Context of URL Rewriting and HTML Sanitization
【24h】

Taint Inference for Cross-Site Scripting in Context of URL Rewriting and HTML Sanitization

机译:URL重写和HTML消毒的上下文中跨站点脚本的污点推断

获取原文
获取原文并翻译 | 示例
           

摘要

Currently, web applications are gaining in prevalence. In a web application, an input may not be appropriately validated, making the web application susceptible to cross site scripting (XSS), which poses serious security problems for Internet users and websites to whom such trusted web pages belong. A taint inference is a type of information flow analysis technique that is useful in detecting XSS on the client side. However, in existing techniques, two current practical issues have yet to be handled properly. One is URL rewriting, which transforms a standard URL into a clearer and more manageable form. Another is HTML sanitization, which filters an input against blacklists or whitelists of HTML tags or attributes. In this paper, we make an analogy between the taint inference problem and the molecule sequence alignment problem in bioinformatics, and transfer two techniques related to the latter over to the former to solve the aforementioned yet-to-be-handled-properly practical issues. In particular, in our method, URL rewriting is addressed using local sequence alignment and HTML sanitization is modeled by introducing a removal gap penalty. Empirical results demonstrate the effectiveness and efficiency of our method.
机译:当前,Web应用程序正在普及。在Web应用程序中,输入可能未得到适当的验证,从而使Web应用程序容易受到跨站点脚本(XSS)的影响,这给Internet用户和此类信任网页所属的网站带来了严重的安全问题。污点推断是一种信息流分析技术,可用于检测客户端的XSS。但是,在现有技术中,两个当前的实际问题尚未得到适当处理。一种是URL重写,它可以将标准URL转换为更清晰,更易于管理的形式。另一个是HTML清理,它根据HTML标签或属性的黑名单或白名单过滤输入内容。在本文中,我们将生物信息学中的异味推断问题和分子序列比对问题进行类比,并将与后者有关的两种技术转移到前者,以解决上述尚未解决的实际问题。特别是,在我们的方法中,URL重写是使用本地序列比对解决的,而HTML清理是通过引入去除间隙罚分来建模的。实验结果证明了该方法的有效性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号