Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology

被引:0
|
作者
Pooja Chaudhary
B. B. Gupta
A. K. Singh
机构
[1] National Institute of Technology,Department of Computer Engineering
[2] Asia University,International Center for AI and Cyber Security Research and Innovations & Department of Computer Science and Information Engineering
[3] Lebanese American University,undefined
[4] Center for Interdisciplinary Research at University of Petroleum and Energy Studies (UPES),undefined
[5] Research and Innovation Department,undefined
[6] Skyline University College,undefined
来源
Soft Computing | 2023年 / 27卷
关键词
Cross-site scripting (XSS) attack; Self-organizing map algorithm; Smart devices; Internet-of-things (IoT) network; Attack ontology; Smart device security;
D O I
暂无
中图分类号
学科分类号
摘要
Smart devices are equipped with technology that facilitates communication among devices connected via the Internet. These devices are shipped with a user interface that enables users to perform administrative activities using a web browser linked to the device’s server. Cross-site scripting (XSS) is the most prevalent web application vulnerability exploited by attackers to compromise smart devices. In this paper, the authors have designed a framework for shielding smart devices from XSS attacks. It is a machine learning-based attack detection framework which employs self-organizing-map (SOM) to classify XSS attack string. The input vector to the SOM is generated based on attack ontology and the changing behavior of the attack strings in different input fields in the device web interface. Additionally, it also sanitizes the injected attack string to neutralize the harmful effects of attack. The experimental results are obtained using the real-world dataset on the XSS attack. We tested the proposed framework on web interface of two smart devices (TP-link Wi-Fi router and HP color printer) containing hidden XSS vulnerabilities. The observed results unveil the robustness of the proposed work against the existing work as it achieves a high accuracy of 0.9904 on the tested dataset. It is a platform-independent attack detection system deployed on the browser or server side.
引用
收藏
页码:4593 / 4608
页数:15
相关论文
共 48 条
  • [21] Developing a Security Model to Protect Websites from Cross-site Scripting Attacks Using Zend Framework Application
    Elhakeem, Yousra Faisal Gad Mahgoup
    Barry, Bazara I. A.
    [J]. 2013 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRICAL AND ELECTRONICS ENGINEERING (ICCEEE), 2013, : 624 - 629
  • [22] Enhancing smart grid security: A novel approach for efficient attack detection using SMART framework
    Duan Y.
    Zhang Y.
    [J]. Measurement: Sensors, 2024, 32
  • [23] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Jasleen Kaur
    Urvashi Garg
    Gourav Bathla
    [J]. Artificial Intelligence Review, 2023, 56 : 12725 - 12769
  • [24] Detection of cross-site scripting (XSS) attacks using machine learning techniques: a review
    Kaur, Jasleen
    Garg, Urvashi
    Bathla, Gourav
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2023, 56 (11) : 12725 - 12769
  • [25] Dynamic feature selection model for adaptive cross site scripting attack detection using developed multi-agent deep Q learning model
    Thajeel, Isam Kareem
    Samsudin, Khairulmizam
    Hashim, Shaiful Jahari
    Hashim, Fazirulhisyam
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (06)
  • [26] Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning
    Lee, Soyoung
    Wi, Seongil
    Son, Sooel
    [J]. PROCEEDINGS OF THE ACM WEB CONFERENCE 2022 (WWW'22), 2022, : 743 - 754
  • [27] Intelligent blockchain based attack detection framework for cross-chain transaction
    Madhuri, Surisetty
    Vadlamani, Nagalakshmi
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (31) : 76247 - 76265
  • [28] Security risk assessment framework for smart car using the attack tree analysis
    Kong, Hee-Kyung
    Hong, Myoung Ki
    Kim, Tae-Sung
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2018, 9 (03) : 531 - 551
  • [29] Security risk assessment framework for smart car using the attack tree analysis
    Hee-Kyung Kong
    Myoung Ki Hong
    Tae-Sung Kim
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2018, 9 : 531 - 551
  • [30] TT-XSS: A novel taint tracking based dynamic detection framework for DOM Cross-Site Scripting
    Wang, Ran
    Xu, Guangquan
    Zeng, Xianjiao
    Li, Xiaohong
    Feng, Zhiyong
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2018, 118 : 100 - 106