首页> 外文会议>International Conference on Information Science and Security >A XSS Vulnerability Detection Approach based on Simulating Browser Behavior
【24h】

A XSS Vulnerability Detection Approach based on Simulating Browser Behavior

机译:一种基于模拟浏览器行为的XSS漏洞检测方法

获取原文

摘要

Aiming at the XSS vulnerability detection, this paper presents a dynamic detection method based on simulating browser behavior, and designs a web crawler based on a headless browser, which can interpret the JavaScript code and retrieve Ajax content to find the hidden injection points in pages, with full consideration of the web pages containing complex scripts under Web 2.0 environment. Besides, this paper provides a more accurate method to identify XSS vulnerability with XSS attack vectors by examining the runtime behavior of web application, and decides whether the XSS vulnerability exists with black-box test. The experiment results prove that this method works.
机译:针对XSS漏洞检测,本文提出了一种基于模拟浏览器行为的动态检测方法,并根据无头浏览器设计一个Web爬虫,这可以解释JavaScript代码并检索AJAX内容以查找页面中的隐藏注入点,充分考虑Web 2.0环境下包含包含复杂脚本的网页。此外,本文通过检查Web应用程序的运行时行为,提供了一种更准确的方法来识别XSS攻击向量,并决定是否存在黑匣子测试中是否存在XSS漏洞。实验结果证明了这种方法的作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号