Nested context-aware sanitisation and feature injection in clustered templates of JavaScript worms on the cloud-based OSN

dc.contributor.authorGupta, Shashank
dc.date.accessioned2024-10-29T09:48:04Z
dc.date.available2024-10-29T09:48:04Z
dc.date.issued2020
dc.description.abstractThis article presents an enhanced JavaScript feature-injection based framework that obstructs the execution of cross-site scripting (XSS) worms from the virtual machines of cloud-based online social network (OSN). It calculates the features of clustered-sanitised compressed templates of JavaScript attack vectors embedded in the HTTP response messages. Any variation observed in such JavaScript feature set indicates the injection of XSS worms on the cloud-based OSN server. The injected worms will further undergo through the process of nested context-aware sanitisation for its safe interpretation on the web browser. The prototype of our framework was developed in Java and installed in the virtual machines of cloud environment. The experimental evaluation of our framework was performed on the platform of OSN-based web applications deployed in the cloud platform. The performance analysis done revealed that our framework detects the injection of malicious JavaScript code with low false negative rate and acceptable performance overhead.en_US
dc.identifier.urihttps://www.inderscienceonline.com/doi/abs/10.1504/IJICS.2020.105153
dc.identifier.urihttp://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/16279
dc.language.isoenen_US
dc.publisherInder Scienceen_US
dc.subjectComputer Scienceen_US
dc.subjectCloud securityen_US
dc.subjectOnline social networking securityen_US
dc.subjectXSS wormsen_US
dc.subjectJavaScript code injection attacksen_US
dc.subjectContext-aware sanitisationen_US
dc.titleNested context-aware sanitisation and feature injection in clustered templates of JavaScript worms on the cloud-based OSNen_US
dc.typeArticleen_US

Files

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: