• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Mokbal, Fawaz Mahiuob Mohammed (Mokbal, Fawaz Mahiuob Mohammed.) | Wang, Dan (Wang, Dan.) | Wang, Xiaoxi (Wang, Xiaoxi.) | Fu, Lihua (Fu, Lihua.)

收录:

EI Scopus SCIE PubMed

摘要:

The rapid growth of the worldwide web and accompanied opportunities of web applications in various aspects of life have attracted the attention of organizations, governments, and individuals. Consequently, web applications have increasingly become the target of cyberattacks. Notably, cross-site scripting (XSS) attacks on web applications are increasing and have become the critical focus of information security experts' reports. Machine learning (ML) technique has significantly advanced and shown impressive results in the area of cybersecurity. However, XSS training datasets are often limited and significantly unbalanced, which does not meet well-developed ML algorithms' requirements and potentially limits the detection system efficiency. Furthermore, XSS attacks have multiple payload vectors that execute in different ways, resulting in many real threats passing through the detection system undetected. In this study, we propose a conditional Wasserstein generative adversarial network with a gradient penalty to enhance the XSS detection system in a low-resource data environment. The proposed method integrates a conditional generative adversarial network and Wasserstein generative adversarial network with a gradient penalty to obtain necessary data from directivity, which improves the strength of the security system over unbalance data. The proposed method generates synthetic samples of minority class that have identical distribution as real XSS attack scenarios. The augmented data were used to train a new boosting model and subsequently evaluated the model using a real test dataset. Experiments on two unbalanced XSS attack datasets demonstrate that the proposed model generates valid and reliable samples. Furthermore, the samples were indistinguishable from real XSS data and significantly enhanced the detection of XSS attacks compared with state-of-the-art methods.

关键词:

XSS Attack Data augmentation Web applications security Conditional-Wasserstein generative adversarial net Imbalance dataset

作者机构:

  • [ 1 ] [Mokbal, Fawaz Mahiuob Mohammed]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing, Peoples R China
  • [ 2 ] [Wang, Dan]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing, Peoples R China
  • [ 3 ] [Fu, Lihua]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing, Peoples R China
  • [ 4 ] [Mokbal, Fawaz Mahiuob Mohammed]ILMA Univ, Fac Comp Sci, Karachi, Pakistan
  • [ 5 ] [Wang, Xiaoxi]State Grid Management Coll, Beijing, Peoples R China

通讯作者信息:

  • [Mokbal, Fawaz Mahiuob Mohammed]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing, Peoples R China;;[Mokbal, Fawaz Mahiuob Mohammed]ILMA Univ, Fac Comp Sci, Karachi, Pakistan

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

PEERJ COMPUTER SCIENCE

ISSN: 2376-5992

年份: 2020

3 . 8 0 0

JCR@2022

被引次数:

WoS核心集被引频次: 3

SCOPUS被引频次: 14

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 1

归属院系:

在线人数/总访问数:394/5061936
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司