The Detection Method for XSS Attacks on NFV by Using Machine Learning Models
Korrawit Santithanmanan · 2022 International Conference on Decision Aid Sciences and Applications (DASA) · 2022
This paper focuses on Cross-site Scripting (XSS) vulnerabilities that occur in the web-based management interface of Cisco Enterprise’s Network Function Virtualization Infrastructure Software (NFVIS). This paper explores one of the security concerns called openness and programmability on the control plane of NFVI that leads to XSS attacks. The attacker uses the XSS to inject malicious code, typically JavaScript, and send it to other users in the form of a URL to identify which URLs are malicious, the Machine Learning methods including k-NN, Decision Tree, SVM, and Gaussian Naive Bayes classification model are used in this paper to classify the pattern of the attacks. In addition, the performance of each model is also evaluated.