DocumentCode
3232381
Title
XSS Application Worms: New Internet Infestation and Optimized Protective Measures
Author
Shanmugam, Jayamsakthi ; Ponnavaikko, M.
Author_Institution
BITS, Pilani
Volume
3
fYear
2007
fDate
July 30 2007-Aug. 1 2007
Firstpage
1164
Lastpage
1169
Abstract
There has been considerable increase in application layer attacks. Research surveys show that the cross site scripting (XSS) attack is most common among all the application layer attacks. Ajax Web technology, by design makes number of calls to the Web server to process a user request. This increases the bandwidth usage and response time due increase in the number of calls to the Web server. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the additional processing required thereby resulting in increased response time. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the increased response time because of the increase in number of requests. This problem demands an efficient approach to protect the Web application from XSS attacks and to block the malicious attempts from reaching the Web application. This paper presents a thread based solution for efficient process utilization of the Web server and to prevent XSS threats. The proposed solution has been tested using Java/JSP on JBOSS server on around 2000 vulnerable XSS input collected from various research sites, white hat and black hat sites. The model is also tested with the combination of non vulnerable input and vulnerable input to assess the performance. The approach is found to be effective compared to the earlier research works.
Keywords
Internet; Java; file servers; invasive software; Ajax Web technology; Internet infestation; JBOSS server; Java/JSP; Web application; Web server; application layer attacks; cross site scripting attack; optimized protective measures; process utilization; security mechanisms; worms; Bandwidth; Computer hacking; Delay; Internet; Java; Payloads; Protection; Testing; Web pages; Web server; Application-Level Web Security; Component-based Design; security vulnerabilities.;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing, 2007. SNPD 2007. Eighth ACIS International Conference on
Conference_Location
Qingdao
Print_ISBN
978-0-7695-2909-7
Type
conf
DOI
10.1109/SNPD.2007.514
Filename
4288025
Link To Document