DocumentCode :
231034
Title :
Enhanced browser defense for reflected Cross-Site Scripting
Author :
Mewara, Bhawna ; Bairwa, Sheetal ; Gajrani, Jyoti ; Jain, Vinesh
Author_Institution :
Dept. of Inf. Technol. & Comput. Eng, Gov. Eng. Coll., Ajmer, India
fYear :
2014
fDate :
8-10 Oct. 2014
Firstpage :
1
Lastpage :
6
Abstract :
Cross-Site Scripting (XSS) is a common attack technique that lets attackers insert the code in the output application of web page which is referred to the web browser of visitor and then the inserted code executes automatically and steals the sensitive information. In order to prevent the users from XSS attack, many client- side solutions have been implemented; most of them being used are the filters that sanitize the malicious input. However, many of these filters do not provide prevention to the newly designed sophisticated attacks such as multiple points of injection, injection into script etc. This paper proposes and implements an approach based on encoding unfiltered reflections for detecting vulnerable web applications which can be exploited using above mentioned sophisticated attacks. Results prove that the proposed approach provides accurate higher detection rate of exploits. In addition to this, an implementation of blocking the execution of malicious scripts have contributed to XSS-Me: an open source Mozilla Firefox security extension that detects for reflected XSS vulnerabilities which can be considered as an effective solution if it is integrated inside the browser rather than being enforced as an extension.
Keywords :
Web sites; online front-ends; search engines; security of data; Web browser; Web page; XSS attack; XSS-Me; client-side solution; enhanced browser defense; malicious input; malicious script; open source Mozilla Firefox security extension; reflected XSS vulnerability; reflected cross-site scripting; sensitive information; sophisticated attack; unfiltered reflection; vulnerable Web application; Browsers; HTML; Information filters; Security; Testing; Vectors; XSS; attack vectors; defense; filter; special characters;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Reliability, Infocom Technologies and Optimization (ICRITO) (Trends and Future Directions), 2014 3rd International Conference on
Conference_Location :
Noida
Print_ISBN :
978-1-4799-6895-4
Type :
conf
DOI :
10.1109/ICRITO.2014.7014761
Filename :
7014761
Link To Document :
بازگشت