• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Wang, Dan (Wang, Dan.) | Gu, Mingchang (Gu, Mingchang.) | Zhao, Wenbing (Zhao, Wenbing.)

收录:

EI Scopus PKU CSCD

摘要:

To improve the detection results of cross-site scripting (XSS) vulnerability, a dynamic attack vector generation and optimization scheme was proposed based on hidden Markov model. The mutated attack vector was generated by using decision tree model to classify the attack vectors and the code confusion strategy to deform the attack vector. To reduce the interactions between the test phase and the web server, an injection point de-duplication and probe algorithm are designed to remove web pages that do not include XSS vulnerabilities and to avoid detecting the same injection point in different web pages. XPath path location technology was adopted to improve the analysis efficiency for vulnerability detection results. Experimental results show that the proposed method can reduce the response time and the miss report, and improve the detection efficiency. © 2017, Editorial Department of Journal of HEU. All right reserved.

关键词:

Vectors Hidden Markov models Testing Decision trees Efficiency Websites

作者机构:

  • [ 1 ] [Wang, Dan]College of Computer Science, Beijing University of Technology, Beijing; 100124, China
  • [ 2 ] [Gu, Mingchang]College of Computer Science, Beijing University of Technology, Beijing; 100124, China
  • [ 3 ] [Zhao, Wenbing]College of Computer Science, Beijing University of Technology, Beijing; 100124, China

通讯作者信息:

  • [gu, mingchang]college of computer science, beijing university of technology, beijing; 100124, china

电子邮件地址:

查看成果更多字段

相关关键词:

来源 :

Journal of Harbin Engineering University

ISSN: 1006-7043

年份: 2017

期: 11

卷: 38

页码: 1769-1774

被引次数:

WoS核心集被引频次:

SCOPUS被引频次: 11

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 3

在线人数/总访问数:1193/4287993
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司