• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Wang, D. (Wang, D..) | Liu, Y. (Liu, Y..) | Zhao, W. (Zhao, W..) | Fu, L. (Fu, L..) | Du, X. (Du, X..)

Indexed by:

Scopus PKU CSCD

Abstract:

To deal with the problems, such as low coverage of found vulnerability injection points in complex web page, lacking of dynamical analysis for response message from target website faced by the detection system of XSS vulnerability, a method to detect XSS vulnerability based on user's behavior simulation is proposed to make improvement for the detection system of XSS vulnerability on extracting injection points, generating attack test vector and analyzing response results. By searching for a variety of the unformatted injection points through analyzing web page structure as well as taking into consideration the length of the string and the type of the character, the attack test vector is optimized and it can bypass the server filter function and shorten the vulnerability detection time. Test results show that the proposed method can improve the detection coverage rate of the injection point and the detection effect of XSS vulnerability. © 2017, Editorial Office of Journal of Dalian University of Technology. All right reserved.

Keyword:

Detection; Ghost.py; Headless browser; XSS vulnerability

Author Community:

  • [ 1 ] [Wang, D.]College of Computer Science, Beijing University of Technology, Beijing, 100124, China
  • [ 2 ] [Liu, Y.]College of Computer Science, Beijing University of Technology, Beijing, 100124, China
  • [ 3 ] [Zhao, W.]College of Computer Science, Beijing University of Technology, Beijing, 100124, China
  • [ 4 ] [Fu, L.]College of Computer Science, Beijing University of Technology, Beijing, 100124, China
  • [ 5 ] [Du, X.]College of Computer Science, Beijing University of Technology, Beijing, 100124, China

Reprint Author's Address:

  • [Wang, D.]College of Computer Science, Beijing University of TechnologyChina

Show more details

Related Keywords:

Related Article:

Source :

Journal of Dalian University of Technology

ISSN: 1000-8608

Year: 2017

Issue: 3

Volume: 57

Page: 302-307

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 6

Online/Total:723/10551883
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.