...
首页> 外文期刊>Journal of network and computer applications >A survey of detection methods for XSS attacks
【24h】

A survey of detection methods for XSS attacks

机译:XSS攻击检测方法概述

获取原文
获取原文并翻译 | 示例

摘要

Cross-site scripting attack (abbreviated as XSS) is an unremitting problem for the Web applications since the early 2000s. It is a code injection attack on the client-side where an attacker injects malicious payload into a vulnerable Web application. The attacker is often successful in eventually executing the malicious code in an innocent user's browser without the user's knowledge. With an XSS attack, an attacker can perform malicious activities such as cookie stealing, session hijacking, redirection to other malicious sites, downloading of unwanted software and spreading of malware. The primary categories of XSS attacks are: non-persistent and persistent XSS attacks. This survey focuses on studying comprehensively, the detection methods available in the literature for XSS attacks. The detection methods discussed in this study are classified according to their deployment sites and further sub-classified according to the analysis mechanism they employ. Along with discussing the pros and cons of each method, this survey also presents a list of tools that support detection of XSS attacks. We also discuss in detail three preconditions that has to be met in order to successfully launch an XSS attack. One of the prime objectives of this survey is to identify a list of issues and open research challenges. This survey can be used as a foundational reading manual by anyone wishing to understand, assess, establish or design a detection mechanism to counter XSS attack.
机译:自2000年代初以来,跨站点脚本攻击(缩写为XSS)对于Web应用程序来说是一个不懈的难题。这是客户端上的代码注入攻击,攻击者将恶意负载注入易受攻击的Web应用程序。攻击者通常会成功地在无辜的用户浏览器中最终执行恶意代码,而无需用户的了解。借助XSS攻击,攻击者可以执行恶意活动,例如Cookie窃取,会话劫持,重定向到其他恶意站点,下载不需要的软件以及传播恶意软件。 XSS攻击的主要类别是:非持久和持久XSS攻击。这项调查的重点是全面研究XSS攻击文献中可用的检测方法。本研究中讨论的检测方法根据其部署地点进行分类,并根据其采用的分析机制进一步细分。除了讨论每种方法的优缺点外,本调查还列出了支持检测XSS攻击的工具列表。我们还将详细讨论成功启动XSS攻击必须满足的三个先决条件。该调查的主要目标之一是确定问题清单和开放的研究挑战。希望了解,评估,建立或设计用于抵抗XSS攻击的检测机制的任何人都可以将此调查用作基础阅读手册。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号