XSSMitigate: Deep Packet Inspection based XSS Attack Quarantine in Software Defined Networks

被引:2
|
作者
Hubballi, Neminath [1 ]
Singh, Yogendra [1 ]
Garg, Dipin [1 ]
机构
[1] Indian Inst Technol Indore, Indore, India
关键词
Application Layer Attack; HTTP; Cross-Site Scripting; SITE SCRIPTING ATTACKS;
D O I
10.1109/ICCE56470.2023.10043374
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Web applications are used by millions everyday for day-to-day activities. These applications deal with personal and financial data and security of these applications becomes important. Cross-Site Scripting (XSS) is a type of attack which target web applications. These attacks can escalate user privileges and can provide access to unauthorized data compromising users' privacy. In this paper, we present a technique to detect and mitigate the XSS attacks in Software Defined Networks (SDN). Our method has two phases as detection and mitigation. For detecting the attack, we use deep packet inspection on network packets collected at a switch placed in front of web server. Once the attack is detected we block the source of attack by installing appropriate rules at the switch through controller. We experiment within a lab setup and also with real world traces to validate the attack detection. Through simulations we show the feasibility of blocking the attack source for quarantine.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Dynamic Attack-Resilient Routing in Software Defined Networks
    Mohan, Purnima Murali
    Gurusamy, Mohan
    Lim, Teng Joon
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (03): : 1146 - 1160
  • [32] DDoS Attack Detection Method Based on Improved KNN With the Degree of DDoS Attack in Software-Defined Networks
    Dong, Shi
    Sarem, Mudar
    [J]. IEEE ACCESS, 2020, 8 : 5039 - 5048
  • [33] Selective Packet Inspection to Detect DoS Flooding Using Software Defined Networking (SDN)
    Chin, Tommy, Jr.
    Mountrouidou, Xenia
    Li, Xiangyang
    Xiong, Kaiqi
    [J]. 2015 IEEE 35TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW), 2015, : 95 - 99
  • [34] A Software-Defined Network (SDN) based Service Provisioning Scheme for Packet Optical Networks
    Zhou, Yu
    Shang, Yu
    Guo, Bingli
    Yin, Shan
    Li, Xin
    Zhang, Jie
    Huang, Shanguo
    [J]. 2016 ASIA COMMUNICATIONS AND PHOTONICS CONFERENCE (ACP), 2016,
  • [35] Performance Modelling of Preemption-based Packet Scheduling for Data Plane in Software Defined Networks
    Miao, Wang
    Min, Geyong
    Wu, Yulei
    Wang, Haozhe
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON SMART CITY/SOCIALCOM/SUSTAINCOM (SMARTCITY), 2015, : 60 - 65
  • [36] Optical Packet and Circuit Integrated Networks and Software Defined Networking Extension
    Harai, Hiroaki
    Furukawa, Hideaki
    Fujikawa, Kenji
    Miyazawa, Takaya
    Wada, Naoya
    [J]. JOURNAL OF LIGHTWAVE TECHNOLOGY, 2014, 32 (16) : 2751 - 2759
  • [37] Deep Reinforcement Learning-Based Routing on Software-Defined Networks
    Kim, Gyungmin
    Kim, Yohan
    Lim, Hyuk
    [J]. IEEE ACCESS, 2022, 10 : 18121 - 18133
  • [38] An Approach for Unifying Rule Based Deep Packet Inspection
    Munoz, A.
    Sezer, S.
    Burns, D.
    Douglas, G.
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,
  • [39] DLSDN: Deep Learning for DDOS attack detection in Software Defined Networking
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    [J]. 2021 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING (CONFLUENCE 2021), 2021, : 683 - 688
  • [40] Deep Packet Inspection Research Based On Hardware Acceleration
    Guo Lei
    Wang Yadi
    Zhu Ke
    [J]. 2012 INTERNATIONAL CONFERENCE ON INDUSTRIAL CONTROL AND ELECTRONICS ENGINEERING (ICICEE), 2012, : 1984 - 1986