期刊文献+

一种XSS漏洞检测系统分析与设计 被引量:2

Analysis and Design of An XSS Vulnerability Detection System
下载PDF
导出
摘要 近年来跨站脚本(XSS)漏洞占据十大计算机网络安全漏洞第3名位置,对互联网安全形成严重威胁。目前大多数检测方案无法兼顾反射型、存储型和基于文档对象模型的XSS漏洞。为提高检测准确率,设计一种结合黑盒测试与动态污点分析技术的XSS漏洞检测方案并优化XSS攻击向量选择策略。该策略首先筛选XSS攻击向量模版,检测时对应不同注入点实时生成不同XSS攻击向量,并根据过滤规则集测试结果进行反过滤变换。对比实验表明,该方案可以提高XSS漏洞检测能力,同时检测时间开销较小。 Cross-site scripting(XSS)vulnerabilities has ranked the third in the top 10 web security vulnerabilities in recent years,posing a serious threat to Internet security.Currently,most of the detection schemes cannot take into account of all XSS types,including reflective XSS vulnerabilities,storage XSS vulnerabilities and vulnerabilities based on the document object model(DOM).In order to improve the detection accuracy,based on previous research,an XSS vulnerabilities detection scheme combining black box testing and dynamic taint analysis is given,which optimizes the selection strategy of XSS attack vectors.In the scheme,the XSS attack vector templates are screened,and inverse filtering transformation is performed according to the result of the filter rule set test.The comparison experiment shows that this scheme can improve the detection ability of XSS vulnerability and it takes much shorter time than usual.
作者 赵跃华 吴东耀 ZHAO Yue-hua;WU Dong-yao(School of Computer Science&Communication Engineering,Jiangsu University,Zhenjiang 212013,China)
出处 《软件导刊》 2019年第3期162-167,共6页 Software Guide
关键词 跨站脚本漏洞 漏洞检测 黑盒测试 动态污点分析技术 cross-site scripting vulnerabilities vulnerabilities detection black box testing dynamic taint analysis
  • 相关文献

参考文献3

二级参考文献17

  • 1徐良华,孙玉龙,高丰,朱鲁华.基于逆向工程的软件漏洞挖掘技术[J].微计算机信息,2006,22(08X):259-261. 被引量:10
  • 2Johns M, Engelmann B, Posegga J. XSSDS: server-side detection of cross-site scripting attacks[C-I,//Proceedings of Computer Security Applications Conference. IS. 1. ] : IEEE, 2008..335 - 344.
  • 3Klein A. DOM based cross site scripting or XSS of the third kind[-JT. Web Application Security Consortium, 2005,4:59 - 64.
  • 4Jovanovic N, Kruegel C, Kirda E. Pixy.. a static analysis tool for detecting Web application vulnerabilities [J-]. IEEE, 2006,126..258-263.
  • 5Artzi S, Kiezun A, Dolby J, et al. Finding bugs in dynamic web applications E C ff Proceedings of the 2008 International Symposium on Software Testing and Analysis. [-S. 1. 1: ACM, 2008:261 -272.
  • 6Vogt P, Nentwich F, Jovanovic N, et al. Cross site scripting prevention with dynamic data tainting and static analysis[C]//Proceedings of the Network and Dis- tributed System Security Symposium (NDSS). New York, USA..[s. n. ], 2007..95 - 102.
  • 7Tang Zhushou, Zhu Haojin, Cao Zhenfu, et al. LWMxD: lexical based webmail XSS discoverer[,C] ff Proceedings of the First International Workshop on Security in Computers, Networking and Commu- nications. [-S. 1. ] : IEEE, 2008:976 - 981.
  • 8Ismail O, Etoh M, Kadobayashi Y. A proposal and implementation of automatic detection/collection system for cross-site scripting vulnerability [-C3 // Proceedings of the 18th International Conference on Advanced Information Networking and Applications. Washington, D.C. , USA: IEEE. 2004,129 - 136.
  • 9陈嘉迅.论跨站脚本(XSS)攻击的危害、成因及防范[J].网络与信息,2008(9):80-80. 被引量:6
  • 10褚诚云.跨站脚本XSS安全漏洞[J].程序员,2008(11):97-99. 被引量:4

共引文献25

同被引文献17

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部