• DocumentCode
    541936
  • Title

    Auditing the defense against cross site scripting in web applications

  • Author

    Shar, Lwin Khin ; Tan, Hee Beng Kuan

  • Author_Institution
    School of Electrical and Electronic Engineering, Block S2, Nanyang Technological University, Nanyang Avenue 639798, Singapore, Republic of Singapore
  • fYear
    2010
  • fDate
    26-28 July 2010
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Majority attacks to web applications today are mainly carried out through input manipulation in order to cause unintended actions of these applications. These attacks exploit the weaknesses of web applications in preventing the manipulation of inputs. Among these attacks, cross site scripting attack — malicious input is submitted to perform unintended actions on a HTML response page — is a common type of attacks. This paper proposes an approach for thorough auditing of code to defend against cross site scripting attack. Based on the possible methods of implementing defenses against cross site scripting attack, the approach extracts all such defenses implemented in code so that developers, testers or auditors could check the extracted output to examine its adequacy. We have also evaluated the feasibility and effectiveness of the proposed approach by applying it to audit a set of real-world applications.
  • Keywords
    Data mining; Encoding; Feature extraction; Filtering theory; HTML; Input variables; Code Auditing; Cross Site Scripting; Input Validation and Filtering; Static Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), Proceedings of the 2010 International Conference on
  • Conference_Location
    Athens
  • Type

    conf

  • Filename
    5741657