Automatic Examination-Based Whitelist Generation for XSS Attack Detection

1Citations
Citations of this article
2Readers
Mendeley users who have this article in their library.
Get full text

Abstract

When faced with cross-site scripting (XSS) attacks, it is difficult to counter all malicious inputs such that they are rendered completely harmless. In such situations, the introduction of a whitelist-based XSS countermeasure is considered to be an effective and robust approach. However, as the behavior of current web applications is complex, it is difficult to theoretically generate the necessary and sufficient whitelists. To this end, we propose an examination-based approach for whitelist generation instead of a theory-based one. We focus on software tests that are always performed during the final stage of the development process and establish a method to automatically generate whitelists that are consistent with the specifications of each web application. By adding the function for whitelist generation on a web application’s test tool, a whitelist can be generated without changing the development process of a conventional web application. We implement our proposed method and evaluate its effectiveness.

Cite

CITATION STYLE

APA

Inoue, K., Honda, T., Mukaiyama, K., Ohki, T., & Nishigaki, M. (2019). Automatic Examination-Based Whitelist Generation for XSS Attack Detection. In Lecture Notes on Data Engineering and Communications Technologies (Vol. 25, pp. 326–338). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-02613-4_29

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free