期刊文献+

Web前端XSS过滤技术研究 被引量:3

Web Front-end XSS Filtering Technology
下载PDF
导出
摘要 为了应对利用web应用漏洞发起的XSS攻击,提出建立web前端白名单的恶意代码检测技术。在客户端接收服务端发送的非渲染文件数据后,通过web前端搭建的一个基于DOM树的防御平台,对这个非渲染文件做过滤处理,将处理过的文件碎片在浏览器上渲染,导致XSS恶意代码无法执行。技术采用Javascript语言编写,可适用于当前各大主流浏览器。实验结果与分析表明,该系统可成功过滤掉输入代码中的恶意代码,并且保留代码中的非恶意部分,提高了阻止XSS攻击的有效性。 Aiming at XSS vulnerabilities in web application attacks, malicious code detection and filtering technology based on JavaScript is proposed, with focus mainly on the white list filtering of the web Front- end. After receiving the non-rendering file data sent from server by the client, and via the setting-up of a web front-end based on DOM tree defense platform, filtering treatment is done on the non-rendering file, the processed file fragments are rendered in the browser, resulting in non-execution of XSS malicious code. The technology written in Javascript language is applicable to the current major browsers. Experimental results and analysis incidate that the system can successfully filter out the malicious part in the input code, and retain the non-malicious part of the code, thus to improve the effectiveness for prevention of XSS attacks.
作者 高岩 胡勇
出处 《通信技术》 2017年第3期539-544,共6页 Communications Technology
关键词 XSS攻击 web前端 白名单过滤 JAVASCRIPT XSS attacks Web front-end white list filtering Javascript
  • 相关文献

参考文献2

二级参考文献15

  • 1Owasp. Top 10 -2010 [ EB/OL]. http ://www. owasp, org, cn/owagp- project/download/2010_OWASP_Top_I 0/view.
  • 2Owasp[ EB/OL]. https://www, owasp, org/index, php/Cross-site Scripting_(XSS).
  • 3Engin Kirda, Christopher Kruegegl, Giovanni Vigna, et al. Noxes: A client-side solution for mitigating cross-site scripting attacks [ C ]//Pro- ceedings of the 21st ACM Symposium on Applied Computing, 2006: 330 - 337.
  • 4Omar Ismail, Masashi Etoh, Youki Kadobayashi. A Proposal and Im- plementation of Automatic Detection/Collection System for Cross-Site Scripting Vulnerability [ C]//18th International Conference on Ad- vanced Information Networking and Applications (AINA 2004) ,2004, 1:145 - 151.
  • 5Joaquin Garcia-Alfaro, Guillermo Navarro-Arribas. A Survey on Cross- Site Scripting [ S ]. Attacks. arXiv : 0905. 4850vl [ cs. CR ] 29 May 2009.
  • 6Gary Wasserman, Su Zhendong. Static detection of cross-site scripting vulnerabilities [ C ]//Proceedings of the 30th international conference on Software engineering. ACM New York, NY, USA ,2008 : 171 - 180.
  • 7Nanad Jovanovic, Christopher Kruegel, Engin Kirda. A static analysis tool for detecting web application vulnerabilities [ C ]//2006 IEEE Symposium on Security and Privacy,2006:6.
  • 8Acunetix. Web application security [ EB/OL ]. 2010. http ://www. clusif, asso. fr/fr/production/ouvrages/pdf/CLUSIF-2010-Web-appli- cation-security, pdf.
  • 9Stefan Kals, Engin Kirda, Christopher Kruegel. A Web Vulnerability Scanner[ C ]//Proceedings of the 15th international conference on World Wide Web ,2006:247 - 556.
  • 10Snake R. Xss ( cross site scripting) cheat sheet [ EB/OL ] . http :// ha. ckers, org/xss, html.

共引文献7

同被引文献14

引证文献3

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部