DSpace Repository

A client-server JavaScript code rewriting-based framework to detect the XSS worms from online social network

Show simple item record

dc.contributor.author Gupta, Shashank
dc.date.accessioned 2024-10-30T09:23:02Z
dc.date.available 2024-10-30T09:23:02Z
dc.date.issued 2018-05
dc.identifier.uri https://onlinelibrary.wiley.com/doi/full/10.1002/cpe.4646
dc.identifier.uri http://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/16286
dc.description.abstract This article presents a client-server JavaScript code rewriting-based framework that protects and preserves the privacy of online users against XSS worms on Online Social Network (OSN). The server-side generates an estimation graph which is explored for extracting the JavaScript code and shifts such code in a separate file. This shifting is done for completely isolating the untrusted JavaScript code and data. The client-side performs runtime monitoring of the dynamic JavaScript code to recognize the tainted flow of untrusted JavaScript variables. The context of such dynamic tainted variables is determined, for performing the string analysis to examine whether it may be considered as vulnerable point or not. Finally, decoding operation is performed on the obfuscated malicious JavaScript code and the JavaScript code embedded in the parameter values of HTTP request. If match is found, then XSS attack vector is present. Otherwise, it is not. The authors have developed their prototype on the Java development framework and have estimated the malicious script alleviation capability of this proposed work on tested web applications (Humhub, Elgg, WordPress, Joomla, Drupal). en_US
dc.language.iso en en_US
dc.publisher Wiley en_US
dc.subject Computer Science en_US
dc.subject JavaScript code injection attacks en_US
dc.subject Social network en_US
dc.subject XSS worms en_US
dc.title A client-server JavaScript code rewriting-based framework to detect the XSS worms from online social network en_US
dc.type Article en_US


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account