XSSmon: A Perl based IDS for the detection of potential XSS attacks

Christopher M. Frenz, Jong Pil Yoon · 2012

Recent years have seen an explosion in the number of cross site scripting (XSS) incidents effecting Web sites and Web applications. As such, an intrusion detection system (IDS) capable of detecting potential cross site scripting attacks is demonstrated. The IDS involves the capturing of potential client side executable content on a Web page and the hashing of that content. At a future point in time, the Web page is reprocessed for client side executable content and the content rehashed, with any differences in the hash values indicative of a potential XSS attack. It is believed that the described IDS technique would be particularly useful for Web forums and other user content driven site, since the IDS only considers content recognized as potentially executable and not normal text content, such as that which would be typically enclosed in paragraph or heading tags.

Read the paper · More papers on PaperTik