Deploying Hybrid EnsembleMachine Learning Techniques for Effective Cross-Site Scripting (XSS) Attack Detection

被引:0
|
作者
Bacha, Noor Ullah [1 ]
Lu, Songfeng [1 ]
Ur Rehman, Attiq [1 ]
Idrees, Muhammad [2 ]
Ghadi, Yazeed Yasin [3 ]
Alahmadi, Tahani Jaser [4 ]
机构
[1] School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan,430073, China
[2] Department of Computer Science and Engineering, University of Engineering and Technology, Lahore,54000, Pakistan
[3] Department of Computer Science and Software Engineering, Al Ain University, Al Ain Abu, Abu Dhabi,12555, United Arab Emirates
[4] Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, Riyadh,84428, Saudi Arabia
来源
Computers, Materials and Continua | 2024年 / 81卷 / 01期
关键词
Computer crime - Contrastive Learning - Cyber attacks - Deep neural networks - Federated learning - Logistic regression - Network security - Parallel processing systems - Support vector regression;
D O I
10.32604/cmc.2024.054780
中图分类号
学科分类号
摘要
Cross-Site Scripting (XSS) remains a significant threat to web application security, exploiting vulnerabilities to hijack user sessions and steal sensitive data. Traditional detection methods often fail to keep pace with the evolving sophistication of cyber threats. This paper introduces a novel hybrid ensemble learning framework that leverages a combination of advanced machine learning algorithms-Logistic Regression (LR), Support Vector Machines (SVM), eXtreme Gradient Boosting (XGBoost), Categorical Boosting (CatBoost), and Deep Neural Networks (DNN). Utilizing the XSS-Attacks-2021 dataset, which comprises 460 instances across various real-world trafficrelated scenarios, this framework significantly enhances XSS attack detection. Our approach, which includes rigorous feature engineering and model tuning, not only optimizes accuracy but also effectively minimizes false positives (FP) (0.13%) and false negatives (FN) (0.19%). This comprehensive methodology has been rigorously validated, achieving an unprecedented accuracy of 99.87%. The proposed system is scalable and efficient, capable of adapting to the increasing number of web applications and user demands without a decline in performance. It demonstrates exceptional real-time capabilities, with the ability to detect XSS attacks dynamically, maintaining high accuracy and low latency even under significant loads. Furthermore, despite the computational complexity introduced by the hybrid ensemble approach, strategic use of parallel processing and algorithmtuning ensures that the system remains scalable and performs robustly in real-time applications. Designed for easy integration with existing web security systems, our framework supports adaptable Application Programming Interfaces (APIs) and a modular design, facilitating seamless augmentation of current defenses. This innovation represents a significant advancement in cybersecurity, offering a scalable and effective solution for securing modern web applications against evolving threats. © 2024 The Authors.
引用
收藏
页码:707 / 748
相关论文
共 50 条
  • [41] Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology
    Pooja Chaudhary
    B. B. Gupta
    A. K. Singh
    [J]. Soft Computing, 2023, 27 : 4593 - 4608
  • [42] Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology
    Chaudhary, Pooja
    Gupta, B. B.
    Singh, A. K.
    [J]. SOFT COMPUTING, 2023, 27 (08) : 4593 - 4608
  • [43] A study on removal techniques of Cross-Site Scripting from web applications
    Shanmugasundaram, G.
    Ravivarman, S.
    Thangavellu, P.
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPUTATION OF POWER, ENERGY, INFORMATION AND COMMUNICATION (ICCPEIC), 2015, : 436 - 442
  • [44] XSS-SAFE: A Server-Side Approach to Detect and Mitigate Cross-Site Scripting (XSS) Attacks in Java']JavaScript Code
    Gupta, Shashank
    Gupta, B. B.
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2016, 41 (03) : 897 - 920
  • [45] Efficient Detection of Multi-step Cross-Site Scripting Vulnerabilities
    Vernotte, Alexandre
    Dadeau, Frederic
    Lebeau, Franck
    Legeard, Bruno
    Peureux, Fabien
    Piat, Francois
    [J]. INFORMATION SYSTEMS SECURITY (ICISS 2014), 2014, 8880 : 358 - 377
  • [46] XSSDS: Server-side Detection of Cross-site Scripting Attacks
    Johns, Martin
    Engelmann, Bjoern
    Posegga, Joachim
    [J]. 24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 335 - +
  • [47] Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning
    Lee, Soyoung
    Wi, Seongil
    Son, Sooel
    [J]. PROCEEDINGS OF THE ACM WEB CONFERENCE 2022 (WWW'22), 2022, : 743 - 754
  • [48] Payload Recognition and Detection of Cross Site Scripting Attack
    Zalbina, M. Ridwan
    Septian, Tri Wanda
    Stiawan, Deris
    Idris, Moh. Yazid
    Heryanto, Ahmad
    Budiarto, Rahmat
    [J]. 2017 2ND INTERNATIONAL CONFERENCE ON ANTI-CYBER CRIMES (ICACC), 2017, : 172 - 176
  • [49] Defining Cross-Site Scripting Attack Resilience Guidelines Based on BeEF Framework Simulation
    Cvitic, Ivan
    Perakovic, Dragan
    Perisa, Marko
    Sever, Dominik
    [J]. MOBILE NETWORKS & APPLICATIONS, 2023, 28 (04): : 1306 - 1318
  • [50] Detecting Blind Cross-Site Scripting Attacks Using Machine Learning
    Kaur, Gurpreet
    Malik, Yasir
    Samuel, Hamman
    Jaafar, Fehmi
    [J]. 2018 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MACHINE LEARNING (SPML 2018), 2018, : 22 - 25