Behavior-Based Anomaly Detection on the Server Side to Reduce the Effectiveness of Cross Site Scripting Vulnerabilities

Jayamsakthi Shanmugam, M. Ponnavaikko · Third International Conference on Semantics, Knowledge and Grid (SKG 2007) · 2007

Cross-site scripting (XSS) is the top most vulnerability in the Web applications as mentioned by research groups. Every day new evasion mechanisms are found by the hackers due to new technology, new HTML tags and script functionalities introduced. Zero-day attacks exploit the vulnerability before the fix could be issued to protect the Web application users. This demands an efficient approach on the server side to protect the users of the application. The proposed behavior based anomaly detection approach introduces a security layer on top of the Web application, so that the existing Web application remain unchanged whenever a new threat is introduced that demands new security mechanisms. Further application level parameters are introduced to reduce the processing time.

Read the paper · More papers on PaperTik