期刊文献+

基于DOM树的跨站脚本攻击防御技术研究 被引量:1

下载PDF
导出
摘要 跨站脚本是一种回显可执行代码的攻击技术,攻击者通过插入可执行的恶意代码,通过受害者浏览器进行加载执行,传统的XSS防御主要通过浏览器特征库纯文本过滤或服务器后台过滤,但特征库纯文本过滤存在黑名单无法全面、正确地涵盖所有标签、属性等问题。采用一种新的检测技术,在大量的跨站恶意样本数据收集后,借助基于LDA和SVM的分类算法,对跨站恶意代码进行检测,并通过相似度匹配,提高整个检测机制的效率,最终达到快速准确检测跨站恶意代码的目的。
作者 昝家玮 杨勇
出处 《通信与信息技术》 2018年第3期62-67,共6页 Communication & Information Technology
  • 相关文献

参考文献4

二级参考文献35

  • 1Joanne K, Colin P H. Flash vulnerabilities analysis of US educational websites [J]. International Journal of Electronic Security and Digital Forensics, 2010, 3(2): 95-107.
  • 2Amit Y. Cross-site scripting through Flash in gmail based services [EB/OL]. (2012-03-22) [2013-12-10]. http://blog. watchfire, com/wfblog/2010/03/cross-site-scripting-through- flash-in-gmail- based-services, html.
  • 3Ruiz-Martinez A. A survey on solutions and main free tools for privacy enhancing Web communications [J]. Journal of Network and Computer Applications, 2012, 35 (5) : 1473- 1492.
  • 4OWASP. Top ten project [EB/OL]. (2013-12-03) [2013-12- 10]. https://www, owasp, org/index, php/Category: OWASP_ Top_Ten_Project.
  • 5Engin K, Christopher K, Giovanni V, et al. Noxes: A client-side solution for mitigating cross-site scripting attacks [C] //Proc of the 2006 ACM Symp on Applied Computing. New York: ACM, 2006:330-337.
  • 6Ter L M, Venkatakrishnan V N. Blueprint, Robust prevention of cross-site scripting attacks for existing browsers [C] //Proc of the 30th IEEE Syrup on Security and Privacy. Los Alamitos, CA: IEEE Computer Society, 2009: 331-346.
  • 7Yacin N, Prateek S, Dawn S. Document structure integrity: A robust basis for cross-site scripting defense [EB/OL]. 2009[2013-12-10]. http://webblaze, cs. berkeley, edu/dsi. html.
  • 8Adam B, Adrienne P F, Prateek S, et al. Protecting browsers from extension vulnerabilities, EECS-2009-185 [R]. Berkeley: University of California, Berkeley, 2009.
  • 9OWASP. SWFIntruder [EB/OL]. (2008-06-11) [2013-12- 10 ]. https://www, owasp, org/index, php/Category: SWFIntruder.
  • 10HP. SWFScan [EB/OL]. (2013-12-03)[2013-12-10] http:// h30499, www3. hp. com/hpeb/attachments/hpeb/sws-119/ 721/ 1/ HP_FREE_TOOL_SwfScan. zip.

共引文献12

同被引文献12

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部