Dual-Layered Defence Mechanism For Prevention of XSS Attack
Aditi D Anchan, Avanish V Patil, Shreyas Vinayaka Basri K S, M N Surya, S Nagasundari · 2023
Over the years the usage of web applications has been increasing, and with the increase in usage and popularity comes security risks. Cross-site scripting attack is one such threat to web applications. Cross-site scripting also known as XSS is an attack wherein a malicious code is injected into a web application which leads to compromise of user data. One of the biggest effects of XSS is that it can lead to exposing user’s credentials and data. So this paper discusses an approach to mitigate the attack by using a dual-layered defence mechanism. In the first defence layer, a KNN model is used to prevent any attacker from injecting XSS scripts into the application, if the model fails to prevent this attack in the first layer, then a second layer of defence is used which uses a session mapping method where the user’s session is mapped with the user’s system details, these details include IP, OS and browser, so if the attacker tries to log in to the application with the victim’s session and if the system details don't match, then the attacker will be restricted from accessing the application. With this dual-layered defence mechanism in the application, it is very hard for an attacker to access a victim’s account.