A Dynamic Detection Technique for XSS Vulnerabilities

Xin Yu Hou, Xiao Lin Zhao*, Mei Jing Wu, Rui Ma, Yu Peng Chen

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

16 引用 (Scopus)

摘要

This paper studies the principle of vulnerability generation and mechanism of cross-site scripting attack, designs a dynamic cross-site scripting vulnerabilities detection technique based on existing theories of black box vulnerabilities detection. The dynamic detection process contains five steps: crawler, feature construct, attacks simulation, results detection and report generation. Crawling strategy in crawler module and constructing algorithm in feature construct module are key points of this detection process. Finally, according to the detection technique proposed in this paper, a detection tool is accomplished in Linux using python language to detect web applications. Experiments were launched to verify the results and compare with the test results of other existing tools, analyze the usability, advantages and disadvantages of the detection method above, confirm the feasibility of applying dynamic detection technique to cross-site scripting vulnerabilities detection.

源语言英语
主期刊名Proceedings - 2018 4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018
编辑Yinglei Song, Hyunsung Kim, Lan Luo, Noor Zaman
出版商Institute of Electrical and Electronics Engineers Inc.
34-43
页数10
ISBN(电子版)9781538669563
DOI
出版状态已出版 - 4月 2018
活动4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018 - Wuhan, 中国
期限: 20 4月 201822 4月 2018

出版系列

姓名Proceedings - 2018 4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018

会议

会议4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018
国家/地区中国
Wuhan
时期20/04/1822/04/18

指纹

探究 'A Dynamic Detection Technique for XSS Vulnerabilities' 的科研主题。它们共同构成独一无二的指纹。

引用此