Deploying Hybrid EnsembleMachine Learning Techniques for Effective Cross-Site Scripting (XSS) Attack Detection

被引:0
|
作者
Bacha, Noor Ullah [1 ]
Lu, Songfeng [1 ]
Ur Rehman, Attiq [1 ]
Idrees, Muhammad [2 ]
Ghadi, Yazeed Yasin [3 ]
Alahmadi, Tahani Jaser [4 ]
机构
[1] School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan,430073, China
[2] Department of Computer Science and Engineering, University of Engineering and Technology, Lahore,54000, Pakistan
[3] Department of Computer Science and Software Engineering, Al Ain University, Al Ain Abu, Abu Dhabi,12555, United Arab Emirates
[4] Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, Riyadh,84428, Saudi Arabia
来源
Computers, Materials and Continua | 2024年 / 81卷 / 01期
关键词
Computer crime - Contrastive Learning - Cyber attacks - Deep neural networks - Federated learning - Logistic regression - Network security - Parallel processing systems - Support vector regression;
D O I
10.32604/cmc.2024.054780
中图分类号
学科分类号
摘要
Cross-Site Scripting (XSS) remains a significant threat to web application security, exploiting vulnerabilities to hijack user sessions and steal sensitive data. Traditional detection methods often fail to keep pace with the evolving sophistication of cyber threats. This paper introduces a novel hybrid ensemble learning framework that leverages a combination of advanced machine learning algorithms-Logistic Regression (LR), Support Vector Machines (SVM), eXtreme Gradient Boosting (XGBoost), Categorical Boosting (CatBoost), and Deep Neural Networks (DNN). Utilizing the XSS-Attacks-2021 dataset, which comprises 460 instances across various real-world trafficrelated scenarios, this framework significantly enhances XSS attack detection. Our approach, which includes rigorous feature engineering and model tuning, not only optimizes accuracy but also effectively minimizes false positives (FP) (0.13%) and false negatives (FN) (0.19%). This comprehensive methodology has been rigorously validated, achieving an unprecedented accuracy of 99.87%. The proposed system is scalable and efficient, capable of adapting to the increasing number of web applications and user demands without a decline in performance. It demonstrates exceptional real-time capabilities, with the ability to detect XSS attacks dynamically, maintaining high accuracy and low latency even under significant loads. Furthermore, despite the computational complexity introduced by the hybrid ensemble approach, strategic use of parallel processing and algorithmtuning ensures that the system remains scalable and performs robustly in real-time applications. Designed for easy integration with existing web security systems, our framework supports adaptable Application Programming Interfaces (APIs) and a modular design, facilitating seamless augmentation of current defenses. This innovation represents a significant advancement in cybersecurity, offering a scalable and effective solution for securing modern web applications against evolving threats. © 2024 The Authors.
引用
收藏
页码:707 / 748
相关论文
共 50 条
  • [1] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Jasleen Kaur
    Urvashi Garg
    Gourav Bathla
    [J]. Artificial Intelligence Review, 2023, 56 : 12725 - 12769
  • [2] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Kaur, Jasleen
    Garg, Urvashi
    Bathla, Gourav
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2023, 56 (11) : 12725 - 12769
  • [3] Detection of Web Cross-Site Scripting (XSS) Attacks
    Alsaffar, Mohammad
    Aljaloud, Saud
    Mohammed, Badiea Abdulkarem
    Al-Mekhlafi, Zeyad Ghaleb
    Almurayziq, Tariq S.
    Alshammari, Gharbi
    Alshammari, Abdullah
    [J]. ELECTRONICS, 2022, 11 (14)
  • [4] The Detecting Cross-Site Scripting (XSS) Using Machine Learning Methods
    Kascheev, Stanislav
    Olenchikova, Tatyana
    [J]. 2020 GLOBAL SMART INDUSTRY CONFERENCE (GLOSIC), 2020, : 265 - 270
  • [5] Cross-Site Scripting (XSS) Detection Integrating Evidences in Multiple Stages
    Zhang, Jingchi
    Jou, Yu-Tsern
    Li, Xiangyang
    [J]. PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2019, : 7166 - 7175
  • [6] A Survey on Detection and Prevention of Cross-Site Scripting Attack
    Nithya, V.
    Pandian, S. Lakshmana
    Malarvizhi, C.
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (03): : 139 - 151
  • [7] Cross-site scripting (XSS) attacks and mitigation: A survey
    Rodriguez, German E.
    Torres, Jenny G.
    Flores, Pamela
    Benavides, Diego E.
    [J]. COMPUTER NETWORKS, 2020, 166
  • [8] XSS-Dec: A Hybrid Solution to Mitigate Cross-Site Scripting Attacks
    Sundareswaran, Smitha
    Squicciarini, Anna Cinzia
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 223 - 238
  • [9] CROSS SITE SCRIPTING (XSS) ATTACK DETECTION USING INTRUSTION DETECTION SYSTEM
    Gupta, Kunal
    Singh, Rajni Ranjan
    Dixit, Manish
    [J]. 2017 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICICCS), 2017, : 199 - 203
  • [10] Detection of Cross-Site Scripting Attack under Multiple Scenarios
    Das, Debasish
    Sharma, Utpal
    Bhattacharyya, D. K.
    [J]. COMPUTER JOURNAL, 2015, 58 (04): : 808 - 822