期刊文献+

基于爬虫的XSS漏洞检测工具设计与实现 被引量:1

Design and Implementation of XSS Vulnerability Detection Tool Based on Crawler
下载PDF
导出
摘要 当前Web技术发展迅速,与其相关的安全问题也层出不穷。其中XSS攻击方式因具有隐蔽性而带来极大的隐私安全隐患。而目前国内对于XSS漏洞检测的研究较少,仍存在如XSS漏洞自动化检测准确率低等问题。因此,本文提出了一种基于爬虫的检测方案。通过模拟用户行为挖掘web隐藏页面,分析页面结构,更加充分地提取页面注入点。针对存储型XSS漏洞在检测过程中,输出数据不一定在响应页面的情况,提出了一种探子向量测试方法,对页面的注入点与输出点进行对应。同时,基于对现有的XSS攻击方式与变异方法的总结,设计并实现了一个XSS漏洞检测工具,即XSS-finder。最终实验证明,该检测工具的准确率可达82%,与同类工具相比更高。 Currently, Web technology is in a rapid development and its related security problems emerge endlessly. Among them, XSS attack brings huge privacy security risks due to the imperceptibility. At present, few researches exist on XSS vulnerability detection in domestic, and some problems still remain such as low accuracy in automatic detection of XSS vulnerability. Therefore, this paper proposes a detection scheme based on crawler, where the page injection point could be extracted more fully by simulating the user behavior to mine web hidden pages and to analyze the page structure. To address the problem that the output data of the stored XSS vulnerability might not be in the response page during the detection process, a probe vector testing method is proposed to correlate the injection point and output point of the page. Meanwhile, an XSS vulnerability detection tool named XSS-finder is designed and implemented after summarizing the available attack manners and mutation methods of XSS. Finally experimental results show that the accuracy of the designed detection tool reaches 82%, higher than its peers.
作者 韩妍妍 何彦茹 刘培鹤 任慧 张锦圣 HAN Yanyan;HE Yanru;LIU Peihe;Ren Hui;ZHANG Jinsheng(Beijing Electronic Science and Technology Institute,Beijing 100070,P.R.China;Xidian University,Xi’an 710071,Shaanxi,P.R.China)
出处 《北京电子科技学院学报》 2019年第1期7-16,共10页 Journal of Beijing Electronic Science And Technology Institute
基金 中央高校基本科研业务费No.328201801.
关键词 爬虫 XSS漏洞 探子向量 隐藏页面 Crawler XSS vulnerability Probe vector Hide page
  • 相关文献

参考文献8

二级参考文献51

  • 1欧健文,董守斌,蔡斌.模板化网页主题信息的提取方法[J].清华大学学报(自然科学版),2005,45(S1):1743-1747. 被引量:70
  • 2张泽华,饶若楠,凌君逸.基于风险测试揭错能力分析[J].计算机工程,2004,30(B12):72-73. 被引量:4
  • 3周立柱,林玲.聚焦爬虫技术研究综述[J].计算机应用,2005,25(9):1965-1969. 被引量:153
  • 4Chinotec Technologies Company. Paros--for Web Application Security Assessment[EB/OL]. (2008-08-15). http://www, parosproxy. org/index,shtml.
  • 5OWASE OWASP Testing Project[EB/OL]. (2008-08-10). http:// www.owasp.org/.
  • 6Klein A. DOM Based Cross Site Scripting or XSS of the Third Kind[EB/OL]. (2008-07-28). http://www, Webappsec.org/projeets/ articles/071105.html,.
  • 7Fortify Software Inc.. Cross-site Scripting(XSS)[EB/OL]. (2008-04- 07). http://www.owasp.org/index.php/Cross-site Scripting_(XSS).
  • 8Ismail O, Etoh M, Kadobayashi Y. A Proposal and Implementation of Automatic Detection/Collection System for Cross-site Scripting Vulnerability[C]//Proc. of the 18th International Conference on Advanced Information Networking and Applications. Washington D C., USA: IEEE Computer Society. 2004.
  • 9吴芳美等.安全软件测试评估[M].北京:中国铁道出版社,2001.
  • 10Pieter N, Michiel H. Mining Twitter in the cloud: A case study [C]// Proceedings of the 2010 IEEE 3rd International Conference on Cloud Computing, CLOUD 2010. Miami, USA: IEEE Computer Society, 2010: 107 -114.

共引文献178

同被引文献6

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部