A Dynamic Detection Technique for XSS Vulnerabilities

Xin Yu Hou, Xiao Lin Zhao*, Mei Jing Wu, Rui Ma, Yu Peng Chen

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

16 Citations (Scopus)

Abstract

This paper studies the principle of vulnerability generation and mechanism of cross-site scripting attack, designs a dynamic cross-site scripting vulnerabilities detection technique based on existing theories of black box vulnerabilities detection. The dynamic detection process contains five steps: crawler, feature construct, attacks simulation, results detection and report generation. Crawling strategy in crawler module and constructing algorithm in feature construct module are key points of this detection process. Finally, according to the detection technique proposed in this paper, a detection tool is accomplished in Linux using python language to detect web applications. Experiments were launched to verify the results and compare with the test results of other existing tools, analyze the usability, advantages and disadvantages of the detection method above, confirm the feasibility of applying dynamic detection technique to cross-site scripting vulnerabilities detection.

Original languageEnglish
Title of host publicationProceedings - 2018 4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018
EditorsYinglei Song, Hyunsung Kim, Lan Luo, Noor Zaman
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages34-43
Number of pages10
ISBN (Electronic)9781538669563
DOIs
Publication statusPublished - Apr 2018
Event4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018 - Wuhan, China
Duration: 20 Apr 201822 Apr 2018

Publication series

NameProceedings - 2018 4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018

Conference

Conference4th Annual International Conference on Network and Information Systems for Computers, ICNISC 2018
Country/TerritoryChina
CityWuhan
Period20/04/1822/04/18

Keywords

  • black-box testing
  • cross-site scripting(XSS)
  • dynamic detection
  • simulated attack

Fingerprint

Dive into the research topics of 'A Dynamic Detection Technique for XSS Vulnerabilities'. Together they form a unique fingerprint.

Cite this