XSSMitigate: Deep Packet Inspection based XSS Attack Quarantine in Software Defined Networks

被引:2
|
作者
Hubballi, Neminath [1 ]
Singh, Yogendra [1 ]
Garg, Dipin [1 ]
机构
[1] Indian Inst Technol Indore, Indore, India
关键词
Application Layer Attack; HTTP; Cross-Site Scripting; SITE SCRIPTING ATTACKS;
D O I
10.1109/ICCE56470.2023.10043374
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Web applications are used by millions everyday for day-to-day activities. These applications deal with personal and financial data and security of these applications becomes important. Cross-Site Scripting (XSS) is a type of attack which target web applications. These attacks can escalate user privileges and can provide access to unauthorized data compromising users' privacy. In this paper, we present a technique to detect and mitigate the XSS attacks in Software Defined Networks (SDN). Our method has two phases as detection and mitigation. For detecting the attack, we use deep packet inspection on network packets collected at a switch placed in front of web server. Once the attack is detected we block the source of attack by installing appropriate rules at the switch through controller. We experiment within a lab setup and also with real world traces to validate the attack detection. Through simulations we show the feasibility of blocking the attack source for quarantine.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Improved Automated Graph and FCM Based DDoS Attack Detection Mechanism in Software Defined Networks
    Li, Xin
    Fan, Zhijie
    Xiao, Ya
    Xu, Qian
    Zhu, Wenye
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (07): : 2117 - 2127
  • [42] Cyberpulse: A Machine Learning Based Link Flooding Attack Mitigation System for Software Defined Networks
    Rasool, Raihan Ur
    Ashraf, Usman
    Ahmed, Khandakar
    Wang, Hua
    Rafique, Wajid
    Anwar, Zahid
    [J]. IEEE ACCESS, 2019, 7 : 34885 - 34899
  • [43] A Software Deep Packet Inspection System for Network Traffic Analysis and Anomaly Detection
    Song, Wenguang
    Beshley, Mykola
    Przystupa, Krzysztof
    Beshley, Halyna
    Kochan, Orest
    Pryslupskyi, Andrii
    Pieniak, Daniel
    Su, Jun
    [J]. SENSORS, 2020, 20 (06)
  • [44] System Architecture for Deep Packet Inspection in High-speed Networks
    Khazankin, Grigory R.
    Komarov, Sergey
    Kovalev, Danila
    Barsegyan, Artur
    Likhachev, Alexander
    [J]. 2017 SIBERIAN SYMPOSIUM ON DATA SCIENCE AND ENGINEERING (SSDSE), 2017, : 27 - 32
  • [45] FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks
    Wang, Haopei
    Xu, Lei
    Gu, Guofei
    [J]. 2015 45TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, 2015, : 239 - 250
  • [46] WiP: Control Plane Saturation Attack Mitigation in Software Defined Networks
    Hubballi, Neminath
    Patel, Kanishk
    [J]. INFORMATION SYSTEMS SECURITY, ICISS 2022, 2022, 13784 : 235 - 246
  • [47] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    [J]. IEEE ACCESS, 2020, 8 : 132502 - 132513
  • [48] Protection against Flow Table Overflow Attack in Software Defined Networks
    Noh, Sichul Kevin
    Kang, Minjae
    Park, Minho
    [J]. 35TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2021), 2021, : 486 - 490
  • [49] Deep Packet Inspection Using Message Passing Networks (Extended Abstract)
    Jain, Divya
    Lakshmi, K. Vasanta
    Shankar, Priti
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, RAID 2008, 2008, 5230 : 419 - 420
  • [50] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    [J]. IEEE Access, 2020, 8 : 132502 - 132513