Cost-effective detection system of cross-site scripting attacks using hybrid learning approach

被引:12
|
作者
Abu Al-Haija, Qasem [1 ]
机构
[1] Princess Sumaya Univ Technol PSUT, Dept Cybersecur, Amman, Jordan
关键词
Cyberattacks; Cross-site scripting attacks; Machine learning; Cyberattacks detection; Cybersecurity;
D O I
10.1016/j.rineng.2023.101266
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Cross-Site Scripting (XSS) attacks inject malicious code payloads into web application logs, triggering stored cross-site scripting execution when accessing the view-logs interface. The destruction produced by the XSS in-jection susceptibilities is especially significant since the attacker can steal sensitive data such as the stored user's cookies and tokens or control the host remotely by using remote code execution of XSS. For example, if an attacker manages to obtain the cookies of the website administrator, the whole website can be taken over. In this paper, we develop and evaluate the performance of a machine-learning-based XSS detection system for website applications. Particularly, we investigate using three supervised machine learning: optimizable k-nearest neighbours, optimizable naive bays, and hybrid (ensemble) learning of decision trees. To validate the system's efficacy, we employed the XSS-Attacks-2019 dataset consisting of modern real-world traffic-subjected types of classes normal (benign) or anomaly (XSS attack). To verify the performance evaluation, we have used several conventional metrics, including the confusion matrix analysis, the detection accuracy, the detection precision, the detection sensitivity, the harmonic detection means, and the detection time. The experimental results demonstrated the predominance of the hybrid learning-based XSS detection system. The best performance in-dicators peaked at 99.8% (accuracy, precision, and sensitivity) with a very short detection time of 103.1 & mu;Sec. Conclusively, the proposed hybrid model outpaced several recent XSS-attacks detection systems in the same study area.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] A proposed approach for preventing Cross-Site Scripting
    Taha, Twana Assad
    Karabatak, Murat
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 228 - 231
  • [22] Cross-site Scripting Threat Intelligence Detection Based on Deep Learning
    Liu, Zhonglin
    Fang, Yong
    Xu, Yijia
    FRONTIERS IN CYBER SECURITY, FCS 2022, 2022, 1726 : 89 - 104
  • [23] Practical analysis on the algorithm of the Cross the algorithm of the Cross-Site Scripting Attacks
    Abazi, Blerton
    Hajrizi, Edmond
    2022 29TH INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING (IWSSIP), 2022,
  • [24] WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense
    Niakanlahiji, Amirreza
    Jafarian, Jafar Haadi
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [25] Automatic Creation of SQL Injection and Cross-Site Scripting Attacks
    Kiezun, Adam
    Guo, Philip J.
    Jayaraman, Karthick
    Ernst, Michael D.
    2009 31ST INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, PROCEEDINGS, 2009, : 199 - +
  • [26] Prevention of cross-site scripting attacks on current web applications
    Garcia-Alfaro, Joaquin
    Navarro-Arribas, Guillermo
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: COOPIS, DOA, ODBASE, GADA, AND IS, PT 2, PROCEEDINGS, 2007, 4804 : 1770 - +
  • [27] A Survey on Detection Techniques to Prevent Cross-Site Scripting Attacks on Current Web Applications
    Garcia-Alfaro, Joaquin
    Navarro-Arribas, Guillermo
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, 2008, 5141 : 287 - +
  • [28] A Practical Exercise System Using Virtual Machines for Learning Cross-Site Scripting Countermeasures
    Kishimoto, Kazuri
    Taniguchi, Yoshiaki
    Iguchi, Nobukazu
    2020 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TAIWAN), 2020,
  • [29] Mitigating Cross-Site Scripting Attacks with a Content Security Policy
    Yusof, Imran
    Pathan, Al-Sakib Khan
    COMPUTER, 2016, 49 (03) : 56 - 63
  • [30] XGBXSS: An Extreme Gradient Boosting Detection Framework for Cross-Site Scripting Attacks Based on Hybrid Feature Selection Approach and Parameters Optimization
    Mokbal, Fawaz Mahiuob Mohammed
    Wang Dan
    Wang Xiaoxi
    Zhao Wenbin
    Fu Lihua
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58