期刊文献+

基于SVM分类器的XSS攻击检测技术 被引量:11

XSS Attack Detection Technology Based on SVM Classifier
下载PDF
导出
摘要 Web应用高速发展的同时产生了大量安全漏洞,跨站脚本攻击(XSS)就是危害最为严重的Web漏洞之一,而基于规则的传统XSS检测工具难以检测未知的和变形的XSS。为了应对未知的和变形的XSS,文中提出了一种基于支持向量机(SVM)分类器的XSS攻击检测方案。该方案在大量分析XSS攻击样本及其变形样本和正常样本的基础上,提取最具代表性的五维特征并将这些特征向量化,然后进行SVM算法的训练和测试。通过准确率、召回率和误报率3个指标来对分类器的检测效果进行评价,并优化特征提取方式。改进后的SVM分类器与传统工具和普通SVM相比性能均有所提升。 A large number of security vulnerabilities appeare with the development of Web applications,XSS is one of the most harmful Web vulnerabilities.To deal with the unknown XSS,a XSS detection scheme based on support vector machine(SVM)classifier was proposed.The most representative five dimensional features are extracted to support the training of machine algorithms based on a large number of analysis of XSS attack samples.The feasibility of the SVM classifier was verified based on accuracy,recall and false alarm rate.In addition,the characteristics of deformed XSS samples were added to optimize the performance of the classifier.The improved SVM classifier has better performance compared with traditional tools and ordinary SVM.
作者 赵澄 陈君新 姚明海 ZHAO Cheng;CHEN Jun-xin;YAO Ming-hai(College of Information Engineering,Zhejiang University of Technology,Hangzhou 310023,China)
出处 《计算机科学》 CSCD 北大核心 2018年第B11期356-360,共5页 Computer Science
基金 国家自然科学基金(61379123 61402414) 浙江省教育厅资助项目(Y201431815)资助
关键词 跨站脚本攻击 特征向量化 SVM分类器 XSS attack Feature vectorization SVM classifier
  • 相关文献

参考文献2

二级参考文献8

  • 1Joachims T.Text categorization with support vector machines: Learning with many relevant features[].Proceedings of the th European Conference on Machine Learning.1998
  • 2ALMGREN M,,DEBAR H,DACIER M.A lightweight tool fordetecting web server attacks. Proceedings of Network andDistributed Systems Security . 2000
  • 3ALMGREN M,LINDQVIST U.Application-integrated data collection for security monitoring. RAID2001 . 2001
  • 4Garcia V H,Monroy R,Quintana M.Web attack detection using ID3[OL]. http://homepage.cem.itesm.mx/raulm/pub/id3-ids . 2013
  • 5XSSED. http://xssed.com . 2014
  • 6XSS (Cross Site Scripting)Cheat Sheet. http://ha.ckers.org/xssAttacks.xml . 2014
  • 7exploit-db. http://www.exploit-db.com/webapps . 2014
  • 8刘外喜,余顺争.网络编码中ACK类攻击的防御研究[J].小型微型计算机系统,2011,32(7):1354-1359. 被引量:3

共引文献17

同被引文献59

引证文献11

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部