A Deep Learning Approach to Detect Cross-Site Scripting Attack as a Web Application Firewall

Khoerina Sa'adah, Rayhan Ramdhany Hanaputra, Girinoto, Setiyo Cahyono · 2024

In this digitalization era, the transformation of services in various sectors, previously carried out traditionally, turned into web-based services, making it easier to access anytime and anywhere. However, multiple threats, including Cross-site Scripting (XSS) attacks, are becoming more complex. According to the OWASP TOP 10, XSS has been ranked in the top 10 for over a decade. In general, defense-in-depth prevention of XSS vulnerabilities will likely involve several measures and rules that need to be implemented in a Web Application Firewall (WAF). In this research, we conduct the detection model XSS attack developed using a deep learning model approach. Data collected through several open sources were combined to produce a new dataset as input training data. The proposed model achieved a 99.82% accuracy value, 99.70% recall value, and 99.78% F1-score value. We also show how the proposed model is implemented on a Web Application Firewall (WAF) integrated with a web application.

Read the paper · More papers on PaperTik