DSpace logo

Please use this identifier to cite or link to this item: http://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/16285
Title: Defense Against HTML5 XSS Attack Vectors: A Nested Context-Aware Sanitization Technique
Authors: Gupta, Shashank
Keywords: Computer Science
Online Social Network
Java Script
Cross Site Scripting
SQL injection
Cross-site scripting
Issue Date: 2018
Publisher: IEEE
Abstract: The authors suggested an offline and online based model based on nested context aware sanitization method for detection and alleviation of malicious XSS attack vectors for OSN's. The offline mode extracts JS from webpage, calculates features and stores them in the depository for additional usage. The online approach embodies URI link extraction and feature estimation thus detecting anomaly on comparison with offline modes feature repository. The authors have developed their prototype in J avaScript and its infrastructure settings are implemented as an extension on infrastructure settings of browser. Our proposed design is implemented and tested on five OSN platforms vulnerable to XSS. The results estimated have the competency to identify the XSS worms with acceptable little false positives in comparison to recent state of art. The outcome of our design draws upon nested context of JS for efficacious sanitization
URI: https://ieeexplore.ieee.org/abstract/document/8442855
http://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/16285
Appears in Collections:Department of Computer Science and Information Systems

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.