期刊文献+

基于指令集随机化的XSS检测和防御系统 被引量:2

XSS Attack Detection and Prevention System Based on Instruction Set Randomization
原文传递
导出
摘要 针对Web遭受跨站脚本攻击越来越严重的问题,设计了一个基于指令集随机化的服务器端XSS检测和防御模型,并在PhpBB网络论坛系统中进行了实现,通过对实验结果的分析可知,本系统可以很好地检测和防御反射型XSS攻击和存储型XSS攻击,同时能检测和防御因网络或操作系统层漏洞导致的网页篡改和网页挂马等恶意攻击行为。 The authors design a XSS detection and prevention system aimed at solving the problem of website being attacked by increasingly sophisticated and severe cross site scripting. It is implemented with PhpBB forum using instruction set randomization techniques. According to the experimental result, our system not only can detect and prevent reflected XSS and stored XSS, but also can detect the attacks of web page defacement and website based Trojans caused by vulnerabilities from network or operating system layers.
出处 《电子技术(上海)》 2014年第4期8-11,共4页 Electronic Technology
基金 中央高校基本科研业务费专项资金(WK0110000007 WK2101020004) 高等学校博士学科点专项科研基金新教师类资助课题(20113402120026) 安徽省自然科学基金(1208085QF112) 安徽省高等学校优秀青年人才基金(2012SQRL001ZD)
关键词 跨站脚本 指令集随机化 代理 网页挂马 cross site scripting instruction set randomization proxy website embedded by Trojan
  • 相关文献

参考文献11

  • 1OWASP Top Ten Project [EB/OL].https://www.owasp. org/index.php/Category:OWASP_Top_Ten Project.
  • 22010 CWE/SANS Top 25 Most Dangerous Software Errors[EB/OL]. http://cwe.mitre.org/top25/.
  • 3McAllister S, Kirda E, Krugel C. Expanding human interactions for in-depth testing of Web applications [C]//Proc of 11 th Symposium on Recent Advances in Intrusion Detection(RAID),2008:142-149.
  • 4Aeunetix. Aeunetix Web Vulnerability Scanner [EB/OL]. http://www.aeunetix.eom/.
  • 5Balzarotti D, Cova M, Felmetsger V, et al. Saner: Composing static and dynamic analysis to validate sanitization in Web applications[C]//Proc of IEEE Security and Privacy Symposium. 2008: 387-401.
  • 6[美]弗拉纳根.Java Script权威指南(第5版)[M].李强,译.北京:机械工业出版社.2007:348.396.
  • 7Guha A, Krishnamurthi S, Jim T. Using static analysis for Ajax intrusion detection[C]//Proc of the 18th International Conference on World Wide Web. 2009: 561-570.
  • 8Hallaraker O, Vigna G. Detecting malicious JavaScript code in Mozilla[C]//Proc of 10th IEEE International Conference on Engineering of Complex Computer Systems. 2005: 85-94.
  • 9Kirda E, Kruegel C, Vigna G, et al. Noxes: A client-side solution for mitigating cross-site scripting attacks [C]//Proc of 21 st Annual ACM Symposium on Applied Computing. 2006: 330-337.
  • 10Kc G S, Keromytis A D, Prevelakis V. Countering code-injection attacks with instruction-set Randomization[C]//Proceedings of the ACM Computer and Communications Security (CCS) Conference, 2003: 272-280.

同被引文献5

引证文献2

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部