期刊文献+

跨站脚本漏洞渗透测试技术 被引量:5

Cross-site script vulnerability penetration testing technology
下载PDF
导出
摘要 为提升跨站脚本(XSS)漏洞检测方法的检测效果,本文提出了基于隐马尔科夫模型(HMM)的攻击向量动态生成和优化方法。采用决策树模型和代码混淆策略对攻击向量进行分类和变形,获得测试用攻击向量。使用注入点去重处理和探子技术去除一部分不存在XSS漏洞的Web页面,避免重复检测不同Web页面中相同的漏洞注入点,减少测试阶段与Web服务器的交互次数;进一步采用XPath路径定位技术提高漏洞检测结果分析的效率。对比实验结果表明,本文提出的方法降低了响应时间和漏报率,提高了检测效率。 To improve the detection results of cross site scripting(XSS)vulnerability,a dynamic attack vector generation and optimization scheme was proposed based on hidden Markov model.The mutated attack vector was generated by using decision tree model to classify the attack vectors and the code confusion strategy to deform the attack vector.To reduce the interactions between the test phase and the web server,an injection point de duplication and probe algorithm are designed to remove web pages that do not include XSS vulnerabilities and to avoid detecting the same injection point in different web pages.XPath path location technology was adopted to improve the analysis efficiency for vulnerability detection results.Experimental results show that the proposed method can reduce the response time and the miss report,and improve the detection efficiency.
作者 王丹 顾明昌 赵文兵 WANG Dan;GU Mingchang;ZHAO Wenbing(College of Computer Science, Beijing University of Technology, Beijing 100124, China)
出处 《哈尔滨工程大学学报》 EI CAS CSCD 北大核心 2017年第11期1769-1774,共6页 Journal of Harbin Engineering University
基金 国家自然科学基金重大研究计划培育项目(91546111) 北京市自然科学基金项目(4173072) 信息网络安全公安部重点实验室开放课题项目
关键词 跨站脚本漏洞 渗透测试 隐马尔科夫模型 攻击向量 注入点 cross site scripting penetration test hidden Markov model(HMM) attack vector injection point
  • 相关文献

参考文献2

二级参考文献13

  • 1Owasp. Top 10 -2010 [ EB/OL]. http ://www. owasp, org, cn/owagp- project/download/2010_OWASP_Top_I 0/view.
  • 2Owasp[ EB/OL]. https://www, owasp, org/index, php/Cross-site Scripting_(XSS).
  • 3Engin Kirda, Christopher Kruegegl, Giovanni Vigna, et al. Noxes: A client-side solution for mitigating cross-site scripting attacks [ C ]//Pro- ceedings of the 21st ACM Symposium on Applied Computing, 2006: 330 - 337.
  • 4Omar Ismail, Masashi Etoh, Youki Kadobayashi. A Proposal and Im- plementation of Automatic Detection/Collection System for Cross-Site Scripting Vulnerability [ C]//18th International Conference on Ad- vanced Information Networking and Applications (AINA 2004) ,2004, 1:145 - 151.
  • 5Joaquin Garcia-Alfaro, Guillermo Navarro-Arribas. A Survey on Cross- Site Scripting [ S ]. Attacks. arXiv : 0905. 4850vl [ cs. CR ] 29 May 2009.
  • 6Gary Wasserman, Su Zhendong. Static detection of cross-site scripting vulnerabilities [ C ]//Proceedings of the 30th international conference on Software engineering. ACM New York, NY, USA ,2008 : 171 - 180.
  • 7Nanad Jovanovic, Christopher Kruegel, Engin Kirda. A static analysis tool for detecting web application vulnerabilities [ C ]//2006 IEEE Symposium on Security and Privacy,2006:6.
  • 8Acunetix. Web application security [ EB/OL ]. 2010. http ://www. clusif, asso. fr/fr/production/ouvrages/pdf/CLUSIF-2010-Web-appli- cation-security, pdf.
  • 9Stefan Kals, Engin Kirda, Christopher Kruegel. A Web Vulnerability Scanner[ C ]//Proceedings of the 15th international conference on World Wide Web ,2006:247 - 556.
  • 10Snake R. Xss ( cross site scripting) cheat sheet [ EB/OL ] . http :// ha. ckers, org/xss, html.

共引文献13

同被引文献39

引证文献5

二级引证文献18

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部