RXSS Protect: A Browser Extension for Detection of Reflected Cross-Site Scripting Attacks in Real-Time Using Machine Learning

Yaachna Rawoteea, Girish Bekaroo · 2024

With the rise of the internet usage and web applications, Reflected Cross-Site Scripting (RXSS) attacks have become increasingly prevalent, accounting for over 90% of recent XSS incidents. This paper proposes a novel defense mechanism against RXSS through a browser extension, called RXSS Protect, integrated with a machine learning (ML) algorithm. This extension, compatible with Google Chrome, Microsoft Edge, and Mozilla Firefox, employs a Support Vector Machine (SVM) model to detect and block malicious scripts in real-time. The system’s architecture includes a Flask server for running the ML model, a browser extension for client-side operations, and an SQLite database for storing URL data. This approach aims to enhance web browsing security by providing an effective tool against RXSS attacks, with potential for future extensions to other types of cyber threats. The SVM model is trained on a dataset of benign and malicious URLs and XSS payloads. Evaluation focused on answering two key research questions, related to detection accuracy and performance across browsers. Results showed that RXSS Protect achieved a high accuracy of 97.53% in identifying RXSS payloads and relatively good overall performance across browsers.

Read the paper · More papers on PaperTik