首页> 外文期刊>Journal of Organizational and End User Computing >Designing a XSS Defensive Framework for Web Servers Deployed in the Existing Smart City Infrastructure
【24h】

Designing a XSS Defensive Framework for Web Servers Deployed in the Existing Smart City Infrastructure

机译:为部署在现有智能城市基础架构中部署的Web服务器的XSS防御框架

获取原文
获取原文并翻译 | 示例
       

摘要

Cross-site scripting is one of the notable exceptions effecting almost every web application. Hence, this article proposed a framework to negate the impact of the XSS attack on web servers deployed in one of the major applications of the Internet of Things (IoT) i.e. the smart city environment. The proposed framework implements 2 approaches: first, it executes vulnerable flow tracking for filtering injected malicious scripting code in dynamic web pages. Second, it accomplished trusted remark generation and validation for unveiling any suspicious activity in static web pages. Finally, the filtered and modified webpage is interfaced to the user. The prototype of the framework has been evaluated on a suite of real-world web applications to detect XSS attack mitigation capability. The performance analysis of the framework has revealed that this framework recognizes the XSS worms with very low false positives, false negatives and acceptable performance overhead as compared to existent XSS defensive methodologies.
机译:跨站点脚本是几乎每个Web应用程序实现的显着异常之一。因此,本文提出了一个框架,以否定XSS攻击对部署的Web服务器的影响(IOT)即智能城市环境的主要应用程序。所提出的框架实现了2个方法:首先,它执行易受攻击的流量跟踪,用于在动态网页中过滤注入的恶意脚本代码。其次,它完成了可信赖的备注生成和验证,以揭示静态网页中的任何可疑活动。最后,过滤和修改的网页与用户接口。框架的原型已经在一套真实的Web应用程序上进行了评估,以检测XSS攻击缓解能力。框架的性能分析表明,与存在的XSS防御方法相比,此框架具有非常低的误报,假阴性和可接受的性能开销,识别出XSS蠕虫。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号