首页> 外国专利> METHOD, APPARATUS, TERMINAL AND MEDIA FOR DETECTING DOCUMENT OBJECT MODEL-BASED CROSS-SITE SCRIPTING ATTACK VULNERABILITY

METHOD, APPARATUS, TERMINAL AND MEDIA FOR DETECTING DOCUMENT OBJECT MODEL-BASED CROSS-SITE SCRIPTING ATTACK VULNERABILITY

机译:检测基于文档对象模型的跨站脚本攻击易损性的方法,装置,终端和媒体

摘要

Disclosed are a method and apparatus for detecting a document object model (DOM) based cross-site scripting (XSS) vulnerability, an apparatus thereof, and a terminal are provided. The method includes: obtaining a set of parameter-value pairs from an original web address of a web page, where the set of parameter-value pairs comprises at least one parameter-value pair; replacing a parameter value in a parameter-value pair with feature code, to form a test web address for the web page, where the feature code comprises malicious code that comprises a malicious character and is uniquely identified in a DOM tree of the web page; obtaining page content corresponding to the test web address; converting the page content, into the DOM tree; and detecting whether a XSS vulnerability exists in the parameter-value pair, based on the DOM tree and the feature code.
机译:公开了一种用于检测基于文档对象模型(DOM)的跨站点脚本(XSS)漏洞的方法和设备,其设备以及终端。该方法包括:从网页的原始网址获得一组参数-值对,其中所述一组参数-值对包括至少一个参数-值对;用特征码替换参数值对中的参数值,以形成所述网页的测试网址,所述特征码包括恶意代码,所述恶意代码包括恶意字符,并在所述网页的DOM树中唯一标识;获取与测试网址对应的页面内容;将页面内容转换为DOM树;根据DOM树和特征码,检测参数值对中是否存在XSS漏洞。

著录项

  • 公开/公告号US2016267278A1

    专利类型

  • 公开/公告日2016-09-15

    原文格式PDF

  • 申请/专利权人 TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED;

    申请/专利号US201415034363

  • 发明设计人 JIACAI WENG;

    申请日2014-10-10

  • 分类号G06F21/57;

  • 国家 US

  • 入库时间 2022-08-21 14:38:51

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号