• DocumentCode
    2267804
  • Title

    Risk mitigation for cross site scripting attacks using signature based model on the server side

  • Author

    Shanmugam, Jayamsakthi ; Ponnavaikko, M.

  • Author_Institution
    SRM Univ., Chennai
  • fYear
    2007
  • fDate
    13-15 Aug. 2007
  • Firstpage
    398
  • Lastpage
    405
  • Abstract
    Researchers and industry experts state that the Cross-site Scripting (XSS) is the top most vulnerability in the web applications. Attacks on web applications are increasing with the implementation of newer technologies, new html tags and new JavaScript functions. This demands an efficient approach on the server side to protect the users of the application. The proposed Signature based misuse detection approach introduces a security layer on top of the web application, so that the existing web application remain unchanged whenever a new threat is introduced that demands new security mechanisms. The web pages that are newly introduced in the web application need not be changed to incorporate the security mechanisms as the solution is implemented on top of the web application. To test the effectiveness of this approach, the vulnerable web inputs listed in research sites, black-hat hacker sites and in the black hat hacker sites are considered. The proposed security system was run on JBoss server and tested on those vulnerable inputs collected from the above sites. There are around 100 variants of XSS attacks found during the testing. It has been found that the approach is very effective as it addresses the vulnerabilities at a granular level of tags and attributes, in addition to addressing the XSS vulnerabilities.
  • Keywords
    Internet; Java; security of data; JBoss server; Java script functions; Web applications; black-hat hacker sites; cross site scripting attacks; cross-site scripting; misuse detection; risk mitigation; security mechanism; signature based model; Authentication; Computer hacking; Computer science education; Credit cards; HTML; Java; Security; Testing; Uniform resource locators; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Computational Sciences, 2007. IMSCCS 2007. Second International Multi-Symposiums on
  • Conference_Location
    Iowa City, IA
  • Print_ISBN
    978-0-7695-3039-0
  • Type

    conf

  • DOI
    10.1109/IMSCCS.2007.82
  • Filename
    4392632