首页> 外文期刊>International journal of cloud applications and computing >Enhancing the Browser-Side Context-Aware Sanitization of Suspicious HTML5 Code for Halting the DOM-Based XSS Vulnerabilities in Cloud
【24h】

Enhancing the Browser-Side Context-Aware Sanitization of Suspicious HTML5 Code for Halting the DOM-Based XSS Vulnerabilities in Cloud

机译:增强可疑HTML5代码的浏览器端上下文感知消毒,以中止云中基于DOM的XSS漏洞

获取原文
获取原文并翻译 | 示例

摘要

This article presents a cloud-based framework that thwarts the DOM-based XSS vulnerabilities caused due to the injection of advanced HTML5 attack vectors in the HTML5 web applications. Initially, the framework collects the key modules of web application, extracts the suspicious HTML5 strings from the latent injection points and performs the clustering on such strings based on their level of similarity. Further, it detects the injection of malicious HTML5 code in the script nodes of DOM tree by detecting the variation in the HTML5 code embedded in the HTTP response generated. Any variation observed will simply indicate the injection of suspicious script code. The prototype of our framework was developed in Java and installed in the virtual machines of cloud environment on the Google Chrome extension. The experimental evaluation of our framework was performed on the platform of real world HTML5 web applications deployed in the cloud platform.
机译:本文介绍了一个基于云的框架,该框架可以阻止由于在HTML5 Web应用程序中注入高级HTML5攻击媒介而导致的基于DOM的XSS漏洞。最初,该框架收集Web应用程序的关键模块,从潜在注入点中提取可疑HTML5字符串,并根据它们的相似程度对这些字符串执行聚类。此外,它通过检测嵌入在生成的HTTP响应中的HTML5代码中的变化来检测DOM树的脚本节点中恶意HTML5代码的注入。观察到的任何变化都只会表明已注入可疑脚本代码。我们框架的原型是使用Java开发的,并安装在Google Chrome扩展程序的云环境虚拟机中。对我们框架的实验评估是在部署在云平台上的真实HTML5 Web应用程序平台上进行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号