Robust injection point-based framework for modern applications against XSS vulnerabilities in online social networks

Shashank Gupta, B. Gupta
{"title":"Robust injection point-based framework for modern applications against XSS vulnerabilities in online social networks","authors":"Shashank Gupta, B. Gupta","doi":"10.1504/IJICS.2018.10012568","DOIUrl":null,"url":null,"abstract":"The authors introduced a universal and an automated server-side flexible framework, XSS-explorer, which automatically scrutinises the web applications in order to discover XSS attack vectors. XSS-explorer is capable enough for exploring and recognising all the injection points of web application and produces explicit XSS attack injection investigations for all such injection points. Our approach is based on methods permitting precise filling of injection points of forms with usable info. The identification of such injection points permits our technique to retrieve each possible web page of application, allowing a wider exploration and accelerating the discovery frequency of XSS attack vectors. We evaluate efficiency of our scheme on a suite of open source multimedia applications by applying F-test hypothesis and F-measure. These evaluations indorse that precise filling of the injection points by only usable info confirms an enhanced efficiency of the tests, thus accelerating the recognition rate of XSS attacks.","PeriodicalId":164016,"journal":{"name":"Int. J. Inf. Comput. Secur.","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Int. J. Inf. Comput. Secur.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1504/IJICS.2018.10012568","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

The authors introduced a universal and an automated server-side flexible framework, XSS-explorer, which automatically scrutinises the web applications in order to discover XSS attack vectors. XSS-explorer is capable enough for exploring and recognising all the injection points of web application and produces explicit XSS attack injection investigations for all such injection points. Our approach is based on methods permitting precise filling of injection points of forms with usable info. The identification of such injection points permits our technique to retrieve each possible web page of application, allowing a wider exploration and accelerating the discovery frequency of XSS attack vectors. We evaluate efficiency of our scheme on a suite of open source multimedia applications by applying F-test hypothesis and F-measure. These evaluations indorse that precise filling of the injection points by only usable info confirms an enhanced efficiency of the tests, thus accelerating the recognition rate of XSS attacks.
针对在线社交网络中XSS漏洞的现代应用程序健壮的基于注入点的框架
作者介绍了一个通用且自动化的服务器端灵活框架XSS-explorer,它可以自动检查web应用程序以发现XSS攻击向量。XSS-explorer有足够的能力探索和识别web应用程序的所有注入点,并为所有这些注入点产生显式的XSS攻击注入调查。我们的方法是基于允许使用可用信息精确填充表单注入点的方法。这些注入点的识别使我们的技术能够检索每个可能的应用程序网页,从而允许更广泛的探索并加快XSS攻击向量的发现频率。我们通过f检验假设和f度量来评估我们的方案在一套开源多媒体应用程序上的效率。这些评估表明,仅用可用信息精确填充注入点可以提高测试的效率,从而提高XSS攻击的识别率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信