Deploying Hybrid EnsembleMachine Learning Techniques for Effective Cross-Site Scripting (XSS) Attack Detection

被引:0
|
作者
Bacha, Noor Ullah [1 ]
Lu, Songfeng [1 ]
Ur Rehman, Attiq [1 ]
Idrees, Muhammad [2 ]
Ghadi, Yazeed Yasin [3 ]
Alahmadi, Tahani Jaser [4 ]
机构
[1] School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan,430073, China
[2] Department of Computer Science and Engineering, University of Engineering and Technology, Lahore,54000, Pakistan
[3] Department of Computer Science and Software Engineering, Al Ain University, Al Ain Abu, Abu Dhabi,12555, United Arab Emirates
[4] Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, Riyadh,84428, Saudi Arabia
来源
Computers, Materials and Continua | 2024年 / 81卷 / 01期
关键词
Computer crime - Contrastive Learning - Cyber attacks - Deep neural networks - Federated learning - Logistic regression - Network security - Parallel processing systems - Support vector regression;
D O I
10.32604/cmc.2024.054780
中图分类号
学科分类号
摘要
Cross-Site Scripting (XSS) remains a significant threat to web application security, exploiting vulnerabilities to hijack user sessions and steal sensitive data. Traditional detection methods often fail to keep pace with the evolving sophistication of cyber threats. This paper introduces a novel hybrid ensemble learning framework that leverages a combination of advanced machine learning algorithms-Logistic Regression (LR), Support Vector Machines (SVM), eXtreme Gradient Boosting (XGBoost), Categorical Boosting (CatBoost), and Deep Neural Networks (DNN). Utilizing the XSS-Attacks-2021 dataset, which comprises 460 instances across various real-world trafficrelated scenarios, this framework significantly enhances XSS attack detection. Our approach, which includes rigorous feature engineering and model tuning, not only optimizes accuracy but also effectively minimizes false positives (FP) (0.13%) and false negatives (FN) (0.19%). This comprehensive methodology has been rigorously validated, achieving an unprecedented accuracy of 99.87%. The proposed system is scalable and efficient, capable of adapting to the increasing number of web applications and user demands without a decline in performance. It demonstrates exceptional real-time capabilities, with the ability to detect XSS attacks dynamically, maintaining high accuracy and low latency even under significant loads. Furthermore, despite the computational complexity introduced by the hybrid ensemble approach, strategic use of parallel processing and algorithmtuning ensures that the system remains scalable and performs robustly in real-time applications. Designed for easy integration with existing web security systems, our framework supports adaptable Application Programming Interfaces (APIs) and a modular design, facilitating seamless augmentation of current defenses. This innovation represents a significant advancement in cybersecurity, offering a scalable and effective solution for securing modern web applications against evolving threats. © 2024 The Authors.
引用
收藏
页码:707 / 748
相关论文
共 50 条
  • [21] Machine Learning-Driven Detection of Cross-Site Scripting Attacks
    Alhamyani, Rahmah
    Alshammari, Majid
    [J]. INFORMATION, 2024, 15 (07)
  • [22] Cross-site Scripting Threat Intelligence Detection Based on Deep Learning
    Liu, Zhonglin
    Fang, Yong
    Xu, Yijia
    [J]. FRONTIERS IN CYBER SECURITY, FCS 2022, 2022, 1726 : 89 - 104
  • [23] Cross-site scripting viruses and worms - a new attack vector
    NGS Software
    [J]. Netw. Secur., 2006, 7 (7-8):
  • [24] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12) : 4008 - 4023
  • [25] Analysis and Prevention for Cross-site Scripting Attack Based on Encoding
    Ding Lan
    Wu ShuTing
    Ye Xing
    Zhang Wei
    [J]. 2013 IEEE 4TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC), 2014, : 102 - 105
  • [26] An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments
    Li, Xiaolong
    Wang, Tingting
    Zhang, Wei
    Niu, Xu
    Zhang, Tingyu
    Zhao, Tengteng
    Wang, Yongji
    Wang, Yufei
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [27] Cross-Site Scripting (XSS) attacks and defense mechanisms: classification and state-of-the-art
    Gupta S.
    Gupta B.B.
    [J]. International Journal of System Assurance Engineering and Management, 2017, 8 (Suppl 1) : 512 - 530
  • [28] An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments
    Xiaolong Li
    Tingting Wang
    Wei Zhang
    Xu Niu
    Tingyu Zhang
    Tengteng Zhao
    Yongji Wang
    Yufei Wang
    [J]. Journal of Cloud Computing, 12
  • [29] TT-XSS: A novel taint tracking based dynamic detection framework for DOM Cross-Site Scripting
    Wang, Ran
    Xu, Guangquan
    Zeng, Xianjiao
    Li, Xiaohong
    Feng, Zhiyong
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2018, 118 : 100 - 106
  • [30] Machine Learning based Cross-site Scripting Detection in Online Social Network
    Wang, Rui
    Jia, Xiaoqi
    Li, Qinlei
    Zhang, Shengzhi
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, 2014 IEEE 6TH INTL SYMP ON CYBERSPACE SAFETY AND SECURITY, 2014 IEEE 11TH INTL CONF ON EMBEDDED SOFTWARE AND SYST (HPCC,CSS,ICESS), 2014, : 823 - 826