• DocumentCode
    3232381
  • Title

    XSS Application Worms: New Internet Infestation and Optimized Protective Measures

  • Author

    Shanmugam, Jayamsakthi ; Ponnavaikko, M.

  • Author_Institution
    BITS, Pilani
  • Volume
    3
  • fYear
    2007
  • fDate
    July 30 2007-Aug. 1 2007
  • Firstpage
    1164
  • Lastpage
    1169
  • Abstract
    There has been considerable increase in application layer attacks. Research surveys show that the cross site scripting (XSS) attack is most common among all the application layer attacks. Ajax Web technology, by design makes number of calls to the Web server to process a user request. This increases the bandwidth usage and response time due increase in the number of calls to the Web server. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the additional processing required thereby resulting in increased response time. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the increased response time because of the increase in number of requests. This problem demands an efficient approach to protect the Web application from XSS attacks and to block the malicious attempts from reaching the Web application. This paper presents a thread based solution for efficient process utilization of the Web server and to prevent XSS threats. The proposed solution has been tested using Java/JSP on JBOSS server on around 2000 vulnerable XSS input collected from various research sites, white hat and black hat sites. The model is also tested with the combination of non vulnerable input and vulnerable input to assess the performance. The approach is found to be effective compared to the earlier research works.
  • Keywords
    Internet; Java; file servers; invasive software; Ajax Web technology; Internet infestation; JBOSS server; Java/JSP; Web application; Web server; application layer attacks; cross site scripting attack; optimized protective measures; process utilization; security mechanisms; worms; Bandwidth; Computer hacking; Delay; Internet; Java; Payloads; Protection; Testing; Web pages; Web server; Application-Level Web Security; Component-based Design; security vulnerabilities.;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing, 2007. SNPD 2007. Eighth ACIS International Conference on
  • Conference_Location
    Qingdao
  • Print_ISBN
    978-0-7695-2909-7
  • Type

    conf

  • DOI
    10.1109/SNPD.2007.514
  • Filename
    4288025