Cost-effective detection system of cross-site scripting attacks using hybrid learning approach

被引:12
|
作者
Abu Al-Haija, Qasem [1 ]
机构
[1] Princess Sumaya Univ Technol PSUT, Dept Cybersecur, Amman, Jordan
关键词
Cyberattacks; Cross-site scripting attacks; Machine learning; Cyberattacks detection; Cybersecurity;
D O I
10.1016/j.rineng.2023.101266
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Cross-Site Scripting (XSS) attacks inject malicious code payloads into web application logs, triggering stored cross-site scripting execution when accessing the view-logs interface. The destruction produced by the XSS in-jection susceptibilities is especially significant since the attacker can steal sensitive data such as the stored user's cookies and tokens or control the host remotely by using remote code execution of XSS. For example, if an attacker manages to obtain the cookies of the website administrator, the whole website can be taken over. In this paper, we develop and evaluate the performance of a machine-learning-based XSS detection system for website applications. Particularly, we investigate using three supervised machine learning: optimizable k-nearest neighbours, optimizable naive bays, and hybrid (ensemble) learning of decision trees. To validate the system's efficacy, we employed the XSS-Attacks-2019 dataset consisting of modern real-world traffic-subjected types of classes normal (benign) or anomaly (XSS attack). To verify the performance evaluation, we have used several conventional metrics, including the confusion matrix analysis, the detection accuracy, the detection precision, the detection sensitivity, the harmonic detection means, and the detection time. The experimental results demonstrated the predominance of the hybrid learning-based XSS detection system. The best performance in-dicators peaked at 99.8% (accuracy, precision, and sensitivity) with a very short detection time of 103.1 & mu;Sec. Conclusively, the proposed hybrid model outpaced several recent XSS-attacks detection systems in the same study area.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] XSStudent: Proposal to Avoid Cross-Site Scripting (XSS) Attacks in Universities
    Rodriguez, German
    Torres, Jenny
    Flores, Pamela
    Benavides, Eduardo
    Nunez-Agurto, Daniel
    2019 3RD CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2019,
  • [42] A Novel Approach for Detection of SQL Injection and Cross Site Scripting Attacks
    Sonewar, Piyush A.
    Mhetre, Nalini A.
    2015 INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING (ICPC), 2015,
  • [43] Detect Cross-Site Scripting Attacks Using Average Word Embedding and Support Vector Machine
    Mokbal, Fawaz Mahiuob Mohammed
    Wang, Dan
    Wang, Xiaoxi
    International Journal of Network Security, 2022, 24 (01) : 20 - 28
  • [44] A BEHAVIOR-BASED CROSS-SITE SCRIPTING DETECTION TECHNIQUE
    Wang Liang
    Wang Xiuting
    2011 INTERNATIONAL CONFERENCE ON COMPUTER AND COMPUTATIONAL INTELLIGENCE (ICCCI 2011), 2012, : 519 - 523
  • [45] A Source Code Cross-site Scripting Vulnerability Detection Method
    Chen, Mu
    Chen, Lu
    Shao, Zhipeng
    Dai, Zaojian
    Li, Nige
    Huang, Xingjie
    Dang, Qian
    Zhao, Xinjian
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2023, 17 (06): : 1689 - 1705
  • [46] XSS-GUARD: Precise dynamic prevention of cross-site scripting attacks
    Bisht, Prithvi
    Venkatakrishnan, V. N.
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, 2008, 5137 : 23 - 43
  • [47] Detection of Cross-Site Scripting Attack under Multiple Scenarios
    Das, Debasish
    Sharma, Utpal
    Bhattacharyya, D. K.
    COMPUTER JOURNAL, 2015, 58 (04): : 808 - 822
  • [48] Detecting Cross-Site Scripting in Web Applications Using Fuzzy Inference System
    Ayeni, Bakare K.
    Sahalu, Junaidu B.
    Adeyanju, Kolawole R.
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2018, 2018
  • [49] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12) : 4008 - 4023
  • [50] Moving Target Defense Against Cross-Site Scripting Attacks (Position Paper)
    Portner, Joe
    Kerr, Joel
    Chu, Bill
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 85 - 91