...
首页> 外文期刊>Journal of ambient intelligence and humanized computing >Evaluation and monitoring of XSS defensive solutions: a survey, open research issues and future directions
【24h】

Evaluation and monitoring of XSS defensive solutions: a survey, open research issues and future directions

机译:评估和监视XSS防御解决方案:调查,未解决的研究问题和未来方向

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

XSS is well- thought-out to be an industry-wide problem that is affecting the diverse contemporary web platforms. The collection of most recent web application reports revealed that XSS reserved the topmost position among all other cyber-attacks. This survey article wishes to present the improvements related to XSS worm defensive methodologies. We have enlarged our discussion to different classes of XSS attacks, i. e., non-persistent, persistent, DOM-Based and mutation- based XSS attacks that has recently stated in the state-of-art. This complete survey offers full vision into the classification, avoidance, recognition and alleviation mechanisms of such attacks. In addition, broad solution classification has been designed for the classification of approaches used by numerous contributions. This article discusses the impact of real world XSS worms and the associated recent real world incidents of such worms. Existing client-side, server-side, proxy-enabled and certain other XSS defensive techniques was presented with an aim to recognize their key contributions and the current performance concerns. In the end, we present certain future research guidelines, a complete mechanism and the associated requirements towards the designing of an effective and robust XSS defensive methodology.
机译:众所周知,XSS是影响整个当代Web平台的行业范围问题。最新的Web应用程序报告的收集表明,XSS在所有其他网络攻击中都保持着最高的位置。这篇调查文章希望介绍与XSS蠕虫防御方法有关的改进。我们将讨论范围扩大到不同类别的XSS攻击,即例如,最近在现有技术中提到的非持久性,持久性,基于DOM和基于变异的XSS攻击。这份完整的调查可以全面了解此类攻击的分类,避免,识别和缓解机制。此外,针对众多贡献者所使用方法的分类,设计了广泛的解决方案分类。本文讨论了真实世界XSS蠕虫的影响以及与之相关的近期现实事件。提出了现有的客户端,服务器端,启用代理的技术以及某些其他XSS防御技术,旨在认识到它们的关键作用和当前的性能问题。最后,我们提出了一些未来的研究指南,完整的机制以及对设计有效而强大的XSS防御方法的相关要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号