DocumentCode
3111300
Title
A solution to block Cross Site Scripting Vulnerabilities based on Service Oriented Architecture
Author
Shanmugam, Jayamsakthi ; Ponnavaikko, M.
Author_Institution
BITS, Pilani Univ., Pilani, India
fYear
2007
fDate
11-13 July 2007
Firstpage
861
Lastpage
866
Abstract
Research data shows that, about 80% of the web applications are vulnerable to cross site scripting attacks. This is because of the fact that the users are allowed to enter tags in the input control for increasing the flexibility in handling web applications input. This increases the threat to the web application by allowing the hackers to plant worms in the web applications through the features like tags. Further, there are billions of web pages that are developed in different languages like PHP, ASP, JSP, HTML, CGI- PERL, .Net etc. There is no single solution available that can be applied for the web application to prevent XSS that are developed in different languages and deployed in different platforms. This paper presents a new solution to block cross site scripting (XSS) attacks that is independent of the languages in which the web applications are developed and addresses XSS vulnerabilities arise from other interfaces. The solution is modularized, configured, and developed in .Net, XML and XSD. This approach is evaluated in a web application developed in JSP/Servlets deployed in JBOSS application server and is found effective as it provides the flexibility to be used across languages with a very minimal configuration to prevent XSS.
Keywords
Web services; security of data; software architecture; .Net; JBOSS application server; Web pages; XML; block cross site scripting vulnerability; service oriented architecture; Application software; Application specific processors; Computer hacking; Data security; HTML; Information security; Service oriented architecture; Web pages; Web server; XML; Application-level web Security; cross-site; scripting; security vulnerabilities;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Science, 2007. ICIS 2007. 6th IEEE/ACIS International Conference on
Conference_Location
Melbourne, Qld.
Print_ISBN
0-7695-2841-4
Type
conf
DOI
10.1109/ICIS.2007.45
Filename
4276491
Link To Document