An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments

被引:2
|
作者
Li, Xiaolong [1 ]
Wang, Tingting [1 ]
Zhang, Wei [1 ]
Niu, Xu [1 ]
Zhang, Tingyu [1 ]
Zhao, Tengteng [1 ]
Wang, Yongji [2 ]
Wang, Yufei [2 ]
机构
[1] Beijing Inst Control & Elect Technol, Muxidi North St, Beijing 100038, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
关键词
Network security; XSS detection; Bidirectional long-term and short-term memory network; Multi-head Attention mechanism;
D O I
10.1186/s13677-023-00483-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud Computing plays a pivotal role in facilitating the Internet of Things (IoT) and its diverse applications. Users frequently access and store data on remote servers in Cloud Computing environments through web browsers. Consequently, attackers may exploit vulnerabilities in web browsing to embed malicious code into web pages, enabling them to launch attacks on remote servers in Cloud Computing environments. Due to its complexity, prevalence, and significant impact, XSS has consistently been recognized as one of the top ten web security vulnerabilities by OWASP. The existing XSS detection technology requires optimization: manual feature extraction is time-consuming and heavily reliant on domain knowledge, while the current confusion technology and complex code logic contribute to a decline in the identification of XSS attacks. This paper proposes a character-level bidirectional long-term and short-term memory network model based on a multi-attention mechanism. The bidirectional long-term and short-term memory network ensures the association of current features with preceding and subsequent text, while the multi-attention mechanism extracts additional features from different feature subspaces to enhance the understanding of text semantics. Experimental results demonstrate the effectiveness of the proposed model for XSS detection, with an F1 score of 98.71%.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments
    Xiaolong Li
    Tingting Wang
    Wei Zhang
    Xu Niu
    Tingyu Zhang
    Tengteng Zhao
    Yongji Wang
    Yufei Wang
    [J]. Journal of Cloud Computing, 12
  • [2] A Survey on Detection and Prevention of Cross-Site Scripting Attack
    Nithya, V.
    Pandian, S. Lakshmana
    Malarvizhi, C.
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (03): : 139 - 151
  • [3] Detection of Cross-Site Scripting Attack under Multiple Scenarios
    Das, Debasish
    Sharma, Utpal
    Bhattacharyya, D. K.
    [J]. COMPUTER JOURNAL, 2015, 58 (04): : 808 - 822
  • [4] Detection and Prevention of Cross-site Scripting Attack with Combined Approaches
    Chen, Hsing-Chung
    Nshimiyimana, Aristophane
    Damarjati, Cahya
    Chang, Pi-Hsien
    [J]. 2021 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2021,
  • [5] Cross-site scripting attack detection based on a modified convolution neural network
    Yan, Huyong
    Feng, Li
    Yu, You
    Liao, Weiling
    Feng, Lei
    Zhang, Jingyue
    Liu, Dan
    Zou, Ying
    Liu, Chongwen
    Qu, Linfa
    Zhang, Xiaoman
    [J]. FRONTIERS IN COMPUTATIONAL NEUROSCIENCE, 2022, 16
  • [6] Analysis and Prevention for Cross-site Scripting Attack Based on Encoding
    Ding Lan
    Wu ShuTing
    Ye Xing
    Zhang Wei
    [J]. 2013 IEEE 4TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC), 2014, : 102 - 105
  • [7] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12) : 4008 - 4023
  • [8] A BEHAVIOR-BASED CROSS-SITE SCRIPTING DETECTION TECHNIQUE
    Wang Liang
    Wang Xiuting
    [J]. 2011 INTERNATIONAL CONFERENCE ON COMPUTER AND COMPUTATIONAL INTELLIGENCE (ICCCI 2011), 2012, : 519 - 523
  • [9] Static Detection of Cross-Site Scripting Vulnerabilities
    Wassermann, Gary
    Su, Zhendong
    [J]. ICSE'08 PROCEEDINGS OF THE THIRTIETH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 2008, : 171 - 180
  • [10] Cross-site scripting viruses and worms - a new attack vector
    NGS Software
    [J]. Netw. Secur, 2006, 7 (7-8):