Cost-effective detection system of cross-site scripting attacks using hybrid learning approach

被引:5
|
作者
Abu Al-Haija, Qasem [1 ]
机构
[1] Princess Sumaya Univ Technol PSUT, Dept Cybersecur, Amman, Jordan
关键词
Cyberattacks; Cross-site scripting attacks; Machine learning; Cyberattacks detection; Cybersecurity;
D O I
10.1016/j.rineng.2023.101266
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Cross-Site Scripting (XSS) attacks inject malicious code payloads into web application logs, triggering stored cross-site scripting execution when accessing the view-logs interface. The destruction produced by the XSS in-jection susceptibilities is especially significant since the attacker can steal sensitive data such as the stored user's cookies and tokens or control the host remotely by using remote code execution of XSS. For example, if an attacker manages to obtain the cookies of the website administrator, the whole website can be taken over. In this paper, we develop and evaluate the performance of a machine-learning-based XSS detection system for website applications. Particularly, we investigate using three supervised machine learning: optimizable k-nearest neighbours, optimizable naive bays, and hybrid (ensemble) learning of decision trees. To validate the system's efficacy, we employed the XSS-Attacks-2019 dataset consisting of modern real-world traffic-subjected types of classes normal (benign) or anomaly (XSS attack). To verify the performance evaluation, we have used several conventional metrics, including the confusion matrix analysis, the detection accuracy, the detection precision, the detection sensitivity, the harmonic detection means, and the detection time. The experimental results demonstrated the predominance of the hybrid learning-based XSS detection system. The best performance in-dicators peaked at 99.8% (accuracy, precision, and sensitivity) with a very short detection time of 103.1 & mu;Sec. Conclusively, the proposed hybrid model outpaced several recent XSS-attacks detection systems in the same study area.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Detecting Cross-Site Scripting Attacks Using Machine Learning
    Mereani, Fawaz A.
    Howe, Jacob M.
    [J]. INTERNATIONAL CONFERENCE ON ADVANCED MACHINE LEARNING TECHNOLOGIES AND APPLICATIONS (AMLTA2018), 2018, 723 : 200 - 210
  • [2] Machine Learning-Driven Detection of Cross-Site Scripting Attacks
    Alhamyani, Rahmah
    Alshammari, Majid
    [J]. INFORMATION, 2024, 15 (07)
  • [3] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Jasleen Kaur
    Urvashi Garg
    Gourav Bathla
    [J]. Artificial Intelligence Review, 2023, 56 : 12725 - 12769
  • [4] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Kaur, Jasleen
    Garg, Urvashi
    Bathla, Gourav
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2023, 56 (11) : 12725 - 12769
  • [5] Detection of Web Cross-Site Scripting (XSS) Attacks
    Alsaffar, Mohammad
    Aljaloud, Saud
    Mohammed, Badiea Abdulkarem
    Al-Mekhlafi, Zeyad Ghaleb
    Almurayziq, Tariq S.
    Alshammari, Gharbi
    Alshammari, Abdullah
    [J]. ELECTRONICS, 2022, 11 (14)
  • [6] Detecting Blind Cross-Site Scripting Attacks Using Machine Learning
    Kaur, Gurpreet
    Malik, Yasir
    Samuel, Hamman
    Jaafar, Fehmi
    [J]. 2018 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MACHINE LEARNING (SPML 2018), 2018, : 22 - 25
  • [7] Deploying Hybrid EnsembleMachine Learning Techniques for Effective Cross-Site Scripting (XSS) Attack Detection
    Bacha, Noor Ullah
    Lu, Songfeng
    Ur Rehman, Attiq
    Idrees, Muhammad
    Ghadi, Yazeed Yasin
    Alahmadi, Tahani Jaser
    [J]. Computers, Materials and Continua, 2024, 81 (01): : 707 - 748
  • [8] Defending against Cross-Site Scripting Attacks
    Shar, Lwin Khin
    Tan, Hee Beng Kuan
    [J]. COMPUTER, 2012, 45 (03) : 55 - 62
  • [9] Noncespaces: Using randomization to defeat cross-site scripting attacks
    Van Gundy, Matthew
    Chen, Hao
    [J]. COMPUTERS & SECURITY, 2012, 31 (04) : 612 - 628
  • [10] XSSDS: Server-side Detection of Cross-site Scripting Attacks
    Johns, Martin
    Engelmann, Bjoern
    Posegga, Joachim
    [J]. 24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 335 - +