Machine and Deep Learning-based XSS Detection Approaches: A Systematic Literature Review

被引:2
|
作者
Thajeel, Isam Kareem [1 ]
Samsudin, Khairulmizam [1 ]
Hashim, Shaiful Jahari [1 ]
Hashim, Fazirulhisyam [1 ]
机构
[1] Univ Putra Malaysia UPM, Fac Engn, Dept Comp & Commun Syst Engn, Serdang 43400, Selangor, Malaysia
关键词
Cross-site scripting (XSS) attacks; Web application security; Cybersecurity; Machine learning; Deep learning; RECURRENT NEURAL-NETWORKS; ATTACK DETECTION; ALGORITHMS; SECURITY;
D O I
10.1016/j.jksuci.2023.101628
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are paramount tools for facilitating services providing in the modern world. Unfortunately, the tremendous growth in the web application usage has resulted in a rise in cyberattacks. Cross-site scripting (XSS) is one of the most frequent cyber security attack vectors that threaten the end user as well as the service provider with the same degree of severity. Recently, an obvious increase of the Machine learning and deep learning ML/DL techniques adoption in XSS attack detection. The goal of this review is to come with a special attention and highlight of Machine learning and deep learning approaches. Thus, in this paper, we present a review of recent advances applied in ML/DL for XSS attack detection and classification. The existing proposed ML/DL approaches for XSS attack detection are analyzed and taxonomized comprehensively in terms of domain areas, data preprocessing, feature extraction, feature selection, dimensionality reduction, Data imbalance, performance metrics, datasets, and data types. Our analysis reveals that the way of how the XSS data is preprocessed considerably impacts the performance and the attack detection models. Proposing a full preprocessing cycle reveals how various ML/DL approaches for XSS attacks detection take advantage of different input data preprocessing techniques. The most used ML/DL and preprocessing stages have also been identified. The limitations of existing ML/DL-based XSS attack detection mechanisms are highlighted to identify the potential gaps and future trends.(c) 2023 The Author(s). Published by Elsevier B.V. on behalf of King Saud University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:24
相关论文
共 50 条
  • [1] A Systematic Literature Review on Explainability for Machine/Deep Learning-based Software Engineering Research
    Cao, Sicong
    Sun, Xiaobing
    Widyasari, Ratnadira
    Lo, David
    Wu, Xiaoxue
    Bo, Lili
    Zhang, Jiale
    Li, Bin
    Liu, Wei
    Wu, Di
    Chen, Yixin
    [J]. arXiv, 1600,
  • [2] A Systematic Literature Review of Deep Learning-Based Detection and Classification Methods for Bacterial Colonies
    Nagro, Shimaa A.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (10) : 185 - 202
  • [3] IoT security with Deep Learning-based Intrusion Detection Systems: A systematic literature review
    Idrissi, Idriss
    Azizi, Mostafa
    Moussaoui, Omar
    [J]. 2020 FOURTH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING IN DATA SCIENCES (ICDS), 2020,
  • [4] A Comprehensive Review of Deep Learning-Based Crack Detection Approaches
    Hamishebahar, Younes
    Guan, Hong
    So, Stephen
    Jo, Jun
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (03):
  • [5] A review of deep learning-based approaches for deepfake content detection
    Passos, Leandro A.
    Jodas, Danilo
    Costa, Kelton A. P.
    Souza, Luis A.
    Rodrigues, Douglas
    Del Ser, Javier
    Camacho, David
    Papa, Joao Paulo
    [J]. EXPERT SYSTEMS, 2024, 41 (08)
  • [6] Machine Learning Approaches for Fake Reviews Detection: A Systematic Literature Review
    Ennaouri, Mohammed
    Zellou, Ahmed
    [J]. JOURNAL OF WEB ENGINEERING, 2023, 22 (05): : 821 - 847
  • [7] Deep learning approaches for bad smell detection: a systematic literature review
    Amal Alazba
    Hamoud Aljamaan
    Mohammad Alshayeb
    [J]. Empirical Software Engineering, 2023, 28
  • [8] Deep learning approaches for bad smell detection: a systematic literature review
    Alazba, Amal
    Aljamaan, Hamoud
    Alshayeb, Mohammad
    [J]. EMPIRICAL SOFTWARE ENGINEERING, 2023, 28 (03)
  • [9] A Systematic Review of Different Categories of Plant Disease Detection Using Deep Learning-Based Approaches
    Yogesh Kumar
    Rupinder Singh
    Manu Raj Moudgil
    [J]. Archives of Computational Methods in Engineering, 2023, 30 : 4757 - 4779
  • [10] Taxonomy of deep learning-based intrusion detection system approaches in fog computing: a systematic review
    Najafli, Sepide
    Haghighat, Abolrazl Toroghi
    Karasfi, Babak
    [J]. KNOWLEDGE AND INFORMATION SYSTEMS, 2024, 66 (11) : 6527 - 6560