XSSmon: A Perl based IDS for the detection of potential XSS attacks
Christopher M. Frenz, Jong Pil Yoon · 2012
Recent years have seen an explosion in the number of cross site scripting (XSS) incidents effecting Web sites and Web applications. As such, an intrusion detection system (IDS) capable of detecting potential cross site scripting attacks is demonstrated. The IDS involves the capturing of potential client side executable content on a Web page and the hashing of that content. At a future point in time, the Web page is reprocessed for client side executable content and the content rehashed, with any differences in the hash values indicative of a potential XSS attack. It is believed that the described IDS technique would be particularly useful for Web forums and other user content driven site, since the IDS only considers content recognized as potentially executable and not normal text content, such as that which would be typically enclosed in paragraph or heading tags.