首页> 外文会议>Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy >XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks
【24h】

XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks

机译:XSS-DEC:一种减轻跨站点脚本攻击的混合解决方案

获取原文

摘要

Cross-site scripting attacks represent one of the major security threats in today's Web applications. Current approaches to mitigate cross-site scripting vulnerabilities rely on either server-based or client-based defense mechanisms. Although effective for many attacks, server-side protection mechanisms may leave the client vulnerable if the server is not well patched. On the other hand, client-based mechanisms may incur a significant overhead on the client system. In this work, we present a hybrid client-server solution that combines the benefits of both architectures. Our Proxy-based solution leverages the strengths of both anomaly detection and control flow analysis to provide accurate detection. We demonstrate the feasibility and accuracy of our approach through extended testing using real-world cross-site scripting exploits.
机译:跨站点脚本攻击代表当今Web应用程序中的主要安全威胁之一。通过基于服务器的基于服务器或客户端的防御机制来缓解跨站点脚本漏洞的当前方法。虽然对许多攻击有效,但如果服务器没有很好地修补,则服务器端保护机制可能会使客户端易受攻击。另一方面,基于客户端的机制可能会在客户端系统上产生显着的开销。在这项工作中,我们介绍了一个混合客户端 - 服务器解决方案,它结合了两个体系结构的好处。我们基于代理的解决方案利用异常检测和控制流程分析的优点来提供精确的检测。我们通过使用现实世界跨站点脚本剥削来展示我们方法的可行性和准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号