DSpace Repository

Detection of Cross-Site Scripting Attacks using Dynamic Analysis and Fuzzy Inference System

Show simple item record

dc.contributor.author Falana, Olorunjube
dc.contributor.author Oloruntoba-Tinubu, Oreoluwa Carolyn
dc.contributor.author Ebo, Ife Olalekan
dc.contributor.author Alaba, Adejimi
dc.date.accessioned 2022-06-16T08:52:30Z
dc.date.available 2022-06-16T08:52:30Z
dc.date.issued 2021-04-13
dc.identifier.citation O. J. Falana, I. O. Ebo, C. O. Tinubu, O. A. Adejimi and A. Ntuk, "Detection of Cross-Site Scripting Attacks using Dynamic Analysis and Fuzzy Inference System," 2020 International Conference in Mathematics, Computer Engineering and Computer Science (ICMCECS), 2020, pp. 1-6, doi: 10.1109/ICMCECS47690.2020.240871. en_US
dc.identifier.uri http://localhost:8080/xmlui/handle/123456789/68
dc.description.abstract Many prevalent problems of web applications are induced by injected codes, which pose great security threats. Vulnerabilities found in web applications are commonly typically exploited to perpetrate attacks. With cross-site scripting (XSS), attackers can infuse malevolent contents into website pages, in this way gaining accessprivileges to sensitive page content of the user such as, session cookies, user’s data or credentials and several other information often kept up by the browser on behalf of the users. This paper presents a hybrid mechanism for detecting XSS attacks using Dynamic Analysis and Fuzzy Inference. The approach scans the website for possible points of injection before generating an attack vector launched via an HTTP request to a web application. The analysis of the HTTP response predicts the presence of an attack vector. The detection capability of the system is evaluated using some active world web applications and the results show a high rate of detection. en_US
dc.description.sponsorship O. J. Falana, I. O. Ebo, C. O. Tinubu, O. A. Adejimi and A. Ntuk en_US
dc.language.iso en en_US
dc.publisher International Conference in Mathematics, Computer Engineering and Computer Science en_US
dc.subject Cross-Site Scripting (XSS), internet, vulnerability, web application, code injection en_US
dc.title Detection of Cross-Site Scripting Attacks using Dynamic Analysis and Fuzzy Inference System en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account