An Execution-flow Based Method for Detecting Cross-Site Scripting of Ajax Applications
Hao Chen, Jianhua Sun, Qianjie Zhang -, Ke Mao - · International Journal of Advancements in Computing Technology · 2010
We present an execution-flow analysis for JavaScript programs running in a web browser to prevent Cross-site Scripting (XSS) attacks. We construct finite-state automata (FSA) to model the client-side behavior of Ajax applications under normal execution. Our system is deployed in proxy mode. The proxy analyzes the execution flow of client-side JavaScript before the requested web pages arrive at the browser to prevent potentially malicious scripts, which do not conform to the FSA. We evaluate our technique against several real-world applications and the result shows that it protects against a variety of XSS attacks with an acceptable performance overhead.