Please use this identifier to cite or link to this item: http://localhost:8080/xmlui/handle/123456789/68
Title: Detection of Cross-Site Scripting Attacks using Dynamic Analysis and Fuzzy Inference System
Authors: Falana, Olorunjube
Oloruntoba-Tinubu, Oreoluwa Carolyn
Ebo, Ife Olalekan
Alaba, Adejimi
Keywords: Cross-Site Scripting (XSS), internet, vulnerability, web application, code injection
Issue Date: 13-Apr-2021
Publisher: International Conference in Mathematics, Computer Engineering and Computer Science
Citation: O. J. Falana, I. O. Ebo, C. O. Tinubu, O. A. Adejimi and A. Ntuk, "Detection of Cross-Site Scripting Attacks using Dynamic Analysis and Fuzzy Inference System," 2020 International Conference in Mathematics, Computer Engineering and Computer Science (ICMCECS), 2020, pp. 1-6, doi: 10.1109/ICMCECS47690.2020.240871.
Abstract: Many prevalent problems of web applications are induced by injected codes, which pose great security threats. Vulnerabilities found in web applications are commonly typically exploited to perpetrate attacks. With cross-site scripting (XSS), attackers can infuse malevolent contents into website pages, in this way gaining accessprivileges to sensitive page content of the user such as, session cookies, user’s data or credentials and several other information often kept up by the browser on behalf of the users. This paper presents a hybrid mechanism for detecting XSS attacks using Dynamic Analysis and Fuzzy Inference. The approach scans the website for possible points of injection before generating an attack vector launched via an HTTP request to a web application. The analysis of the HTTP response predicts the presence of an attack vector. The detection capability of the system is evaluated using some active world web applications and the results show a high rate of detection.
URI: http://localhost:8080/xmlui/handle/123456789/68
Appears in Collections:Computer Science

Files in This Item:
File Description SizeFormat 
crossscriptpdf.pdf732.28 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.