Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology

被引:0
|
作者
Pooja Chaudhary
B. B. Gupta
A. K. Singh
机构
[1] National Institute of Technology,Department of Computer Engineering
[2] Asia University,International Center for AI and Cyber Security Research and Innovations & Department of Computer Science and Information Engineering
[3] Lebanese American University,undefined
[4] Center for Interdisciplinary Research at University of Petroleum and Energy Studies (UPES),undefined
[5] Research and Innovation Department,undefined
[6] Skyline University College,undefined
来源
Soft Computing | 2023年 / 27卷
关键词
Cross-site scripting (XSS) attack; Self-organizing map algorithm; Smart devices; Internet-of-things (IoT) network; Attack ontology; Smart device security;
D O I
暂无
中图分类号
学科分类号
摘要
Smart devices are equipped with technology that facilitates communication among devices connected via the Internet. These devices are shipped with a user interface that enables users to perform administrative activities using a web browser linked to the device’s server. Cross-site scripting (XSS) is the most prevalent web application vulnerability exploited by attackers to compromise smart devices. In this paper, the authors have designed a framework for shielding smart devices from XSS attacks. It is a machine learning-based attack detection framework which employs self-organizing-map (SOM) to classify XSS attack string. The input vector to the SOM is generated based on attack ontology and the changing behavior of the attack strings in different input fields in the device web interface. Additionally, it also sanitizes the injected attack string to neutralize the harmful effects of attack. The experimental results are obtained using the real-world dataset on the XSS attack. We tested the proposed framework on web interface of two smart devices (TP-link Wi-Fi router and HP color printer) containing hidden XSS vulnerabilities. The observed results unveil the robustness of the proposed work against the existing work as it achieves a high accuracy of 0.9904 on the tested dataset. It is a platform-independent attack detection system deployed on the browser or server side.
引用
收藏
页码:4593 / 4608
页数:15
相关论文
共 43 条
  • [1] Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology
    Chaudhary, Pooja
    Gupta, B. B.
    Singh, A. K.
    [J]. SOFT COMPUTING, 2023, 27 (08) : 4593 - 4608
  • [2] A Survey on Detection and Prevention of Cross-Site Scripting Attack
    Nithya, V.
    Pandian, S. Lakshmana
    Malarvizhi, C.
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (03): : 139 - 151
  • [3] Detection of Cross-Site Scripting Attack under Multiple Scenarios
    Das, Debasish
    Sharma, Utpal
    Bhattacharyya, D. K.
    [J]. COMPUTER JOURNAL, 2015, 58 (04): : 808 - 822
  • [4] Detection and Prevention of Cross-site Scripting Attack with Combined Approaches
    Chen, Hsing-Chung
    Nshimiyimana, Aristophane
    Damarjati, Cahya
    Chang, Pi-Hsien
    [J]. 2021 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2021,
  • [5] Cross-site scripting attack detection based on a modified convolution neural network
    Yan, Huyong
    Feng, Li
    Yu, You
    Liao, Weiling
    Feng, Lei
    Zhang, Jingyue
    Liu, Dan
    Zou, Ying
    Liu, Chongwen
    Qu, Linfa
    Zhang, Xiaoman
    [J]. FRONTIERS IN COMPUTATIONAL NEUROSCIENCE, 2022, 16
  • [6] Defining Cross-Site Scripting Attack Resilience Guidelines Based on BeEF Framework Simulation
    Cvitic, Ivan
    Perakovic, Dragan
    Perisa, Marko
    Sever, Dominik
    [J]. MOBILE NETWORKS & APPLICATIONS, 2023, 28 (04): : 1306 - 1318
  • [7] Analysis and Prevention for Cross-site Scripting Attack Based on Encoding
    Ding Lan
    Wu ShuTing
    Ye Xing
    Zhang Wei
    [J]. 2013 IEEE 4TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC), 2014, : 102 - 105
  • [8] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12): : 4008 - 4023
  • [9] An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments
    Li, Xiaolong
    Wang, Tingting
    Zhang, Wei
    Niu, Xu
    Zhang, Tingyu
    Zhao, Tengteng
    Wang, Yongji
    Wang, Yufei
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [10] An LSTM based cross-site scripting attack detection scheme for Cloud Computing environments
    Xiaolong Li
    Tingting Wang
    Wei Zhang
    Xu Niu
    Tingyu Zhang
    Tengteng Zhao
    Yongji Wang
    Yufei Wang
    [J]. Journal of Cloud Computing, 12