• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Liu Yuan (Liu Yuan.) | Zhao Wenbing (Zhao Wenbing.) | Wang Dan (Wang Dan.) | Fu Lihua (Fu Lihua.)

Indexed by:

CPCI-S

Abstract:

Aiming at the XSS vulnerability detection, this paper presents a dynamic detection method based on simulating browser behavior, and designs a web crawler based on a headless browser, which can interpret the JavaScript code and retrieve Ajax content to find the hidden injection points in pages, with full consideration of the web pages containing complex scripts under Web 2.0 environment. Besides, this paper provides a more accurate method to identify XSS vulnerability with XSS attack vectors by examining the runtime behavior of web application, and decides whether the XSS vulnerability exists with black-box test. The experiment results prove that this method works.

Keyword:

black-box test Simulating Browser XSS vulnerability crawler

Author Community:

  • [ 1 ] [Liu Yuan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 2 ] [Zhao Wenbing]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 3 ] [Wang Dan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 4 ] [Fu Lihua]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China

Reprint Author's Address:

  • [Liu Yuan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China

Email:

Show more details

Related Keywords:

Related Article:

Source :

2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY (ICISS)

Year: 2015

Page: 84-87

Language: English

Cited Count:

WoS CC Cited Count: 0

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 8

Online/Total:1009/10532036
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.