...
首页> 外文期刊>Information and software technology >Current state of research on cross-site scripting (XSS) - A systematic literature review
【24h】

Current state of research on cross-site scripting (XSS) - A systematic literature review

机译:跨站点脚本(XSS)的研究现状-系统文献综述

获取原文
获取原文并翻译 | 示例
           

摘要

Context: Cross-site scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications. Objective: To conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks. Method: We followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to cross-site scripting from various journals and conference proceedings. Results: Research on XSS is still very active with publications across many conference proceedings and journals. Attack prevention and vulnerability detection are the areas focused on by most of the studies. Dynamic analysis techniques form the majority among the solutions proposed by the various studies. The type of XSS addressed the most is reflected XSS. Conclusion: XSS still remains a big problem for web applications, despite the bulk of solutions provided so far. There is no single solution that can effectively mitigate XSS attacks. More research is needed in the area of vulnerability removal from the source code of the applications before deployment.
机译:上下文:跨站点脚本(XSS)是影响Web应用程序的安全漏洞。发生此错误是由于用户输入的不当或缺乏消毒。该安全漏洞为用户和服务器应用程序带来了许多问题。目的:对有关XSS漏洞和攻击的研究进行系统的文献综述。方法:我们遵循Barbara Kitchenham所记录的系统文献回顾的标准指南,并回顾了来自各种期刊和会议记录的115项与跨站点脚本相关的研究。结果:关于XSS的研究仍然非常活跃,并且在许多会议论文集和期刊上都有出版物。攻击预防和漏洞检测是大多数研究重点关注的领域。在各种研究提出的解决方案中,动态分析技术占大多数。解决最多的XSS类型反映了XSS。结论:尽管到目前为止提供了大量的解决方案,但是XSS仍然是Web应用程序的大问题。没有单一的解决方案可以有效缓解XSS攻击。在部署之前从应用程序的源代码中消除漏洞方面需要进行更多的研究。

著录项

  • 来源
    《Information and software technology》 |2015年第2期|170-186|共17页
  • 作者单位

    Department of Software Engineering and Information System, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia, 43400 Serdang, Selangor, Malaysia;

    Department of Software Engineering and Information System, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia, 43400 Serdang, Selangor, Malaysia;

    Department of Software Engineering and Information System, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia, 43400 Serdang, Selangor, Malaysia;

    Department of Software Engineering and Information System, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia, 43400 Serdang, Selangor, Malaysia;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Systematic literature review; Cross-site scripting; Security; Web applications;

    机译:系统的文献综述;跨站脚本;安全;网络应用;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号