Cross Site Scripting-Latest developments and solutions: A survey
Jayamsakthi Shanmugam, M. Ponnavaikko · 2008
Research reports indicate that more than 80% of the web applications are vulnerable to XSS threats. User friendly web applications are developed to increase the customer base and hackers utilize the features provided by the web applications. Research report shows that there is a shift in the focus of the cyber criminals and cyber spies to evade the counter measures built within the web applications. The authors have collected around 2800 vulnerable Cross Site Scripting (XSS) web applications which formed the basis for drawing conclusions along with the other researchers report on this problem. Recent trend in the growth of XSS attacks indicate that worms are planted in the web application using XSS mechanisms. This paper surveys such vulnerabilities with the current solutions. Categories of solutions are based on the location (client side or server side), analysis type (static, dynamic, taint, alias, data flow, source code, control flow graph), technique (crawling, reverse engineering, black box testing, proxy server) and intrusion detection type (anomaly, misuse, automatic, multimodal). The strengths and weaknesses of all approaches are discussed. In this article, the authors propose the future line of research based on the gaps in the existing solutions proposed by earlier research work.