• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Liu Yuan (Liu Yuan.) | Zhao Wenbing (Zhao Wenbing.) | Wang Dan (Wang Dan.) | Fu Lihua (Fu Lihua.)

收录:

CPCI-S

摘要:

Aiming at the XSS vulnerability detection, this paper presents a dynamic detection method based on simulating browser behavior, and designs a web crawler based on a headless browser, which can interpret the JavaScript code and retrieve Ajax content to find the hidden injection points in pages, with full consideration of the web pages containing complex scripts under Web 2.0 environment. Besides, this paper provides a more accurate method to identify XSS vulnerability with XSS attack vectors by examining the runtime behavior of web application, and decides whether the XSS vulnerability exists with black-box test. The experiment results prove that this method works.

关键词:

black-box test Simulating Browser XSS vulnerability crawler

作者机构:

  • [ 1 ] [Liu Yuan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 2 ] [Zhao Wenbing]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 3 ] [Wang Dan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 4 ] [Fu Lihua]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China

通讯作者信息:

  • [Liu Yuan]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY (ICISS)

年份: 2015

页码: 84-87

语种: 英文

被引次数:

WoS核心集被引频次: 0

SCOPUS被引频次:

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 3

在线人数/总访问数:174/4299199
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司