Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology

被引:0
|
作者
Pooja Chaudhary
B. B. Gupta
A. K. Singh
机构
[1] National Institute of Technology,Department of Computer Engineering
[2] Asia University,International Center for AI and Cyber Security Research and Innovations & Department of Computer Science and Information Engineering
[3] Lebanese American University,undefined
[4] Center for Interdisciplinary Research at University of Petroleum and Energy Studies (UPES),undefined
[5] Research and Innovation Department,undefined
[6] Skyline University College,undefined
来源
Soft Computing | 2023年 / 27卷
关键词
Cross-site scripting (XSS) attack; Self-organizing map algorithm; Smart devices; Internet-of-things (IoT) network; Attack ontology; Smart device security;
D O I
暂无
中图分类号
学科分类号
摘要
Smart devices are equipped with technology that facilitates communication among devices connected via the Internet. These devices are shipped with a user interface that enables users to perform administrative activities using a web browser linked to the device’s server. Cross-site scripting (XSS) is the most prevalent web application vulnerability exploited by attackers to compromise smart devices. In this paper, the authors have designed a framework for shielding smart devices from XSS attacks. It is a machine learning-based attack detection framework which employs self-organizing-map (SOM) to classify XSS attack string. The input vector to the SOM is generated based on attack ontology and the changing behavior of the attack strings in different input fields in the device web interface. Additionally, it also sanitizes the injected attack string to neutralize the harmful effects of attack. The experimental results are obtained using the real-world dataset on the XSS attack. We tested the proposed framework on web interface of two smart devices (TP-link Wi-Fi router and HP color printer) containing hidden XSS vulnerabilities. The observed results unveil the robustness of the proposed work against the existing work as it achieves a high accuracy of 0.9904 on the tested dataset. It is a platform-independent attack detection system deployed on the browser or server side.
引用
收藏
页码:4593 / 4608
页数:15
相关论文
共 43 条
  • [31] XGBXSS: An Extreme Gradient Boosting Detection Framework for Cross-Site Scripting Attacks Based on Hybrid Feature Selection Approach and Parameters Optimization
    Mokbal, Fawaz Mahiuob Mohammed
    Wang Dan
    Wang Xiaoxi
    Zhao Wenbin
    Fu Lihua
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58
  • [32] REPLAY ATTACK DETECTION USING MAGNITUDE AND PHASE INFORMATION WITH ATTENTION-BASED ADAPTIVE FILTERS
    Liu, Meng
    Wang, Longbiao
    Dang, Jianwu
    Nakagawa, Seiichi
    Guan, Haotian
    Li, Xiangang
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 6201 - 6205
  • [33] A New Cross-site Scripting Detection Mechanism Integrated with HTML']HTML5 and CORS Properties by Using Browser Extensions
    Wang, Chih-Hung
    Zhou, Yi-Shauin
    [J]. 2016 INTERNATIONAL COMPUTER SYMPOSIUM (ICS), 2016, : 264 - 269
  • [34] An intelligent behavioral-based DDOS attack detection method using adaptive time intervals
    Shamekhi, Ali
    Shamsinejad Babaki, Pirooz
    Javidan, Reza
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (04) : 2185 - 2204
  • [35] Artificial intelligence enabled cyber security defense for smart cities: A novel attack detection framework based on the MDATA model
    Jia, Yan
    Gu, Zhaoquan
    Du, Lei
    Long, Yu
    Wang, Ye
    Li, Jianxin
    Zhang, Yanchun
    [J]. KNOWLEDGE-BASED SYSTEMS, 2023, 276
  • [36] AMLFN-AD:Adaptive multi-level integrated fusion attack detection framework for intelligent building systems
    Yuan, Jingling
    Wang, Nana
    Cai, Siqi
    Chen, Mincheng
    Li, Xinping
    [J]. COMPUTER NETWORKS, 2023, 227
  • [37] Intelligent Cyber Security Framework Based on SC-AJS']JSO Feature Selection and HT-RLSTM Attack Detection
    Dahiya, Mahima
    Nitin, Nitin
    Dahiya, Deepak
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (13):
  • [38] An Advance Encryption and Attack Detection Framework for Securing Smart Cities Data in Blockchain Using Deep Learning Approach
    Kumar, Amit
    Kumar, Suresh
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2024, 135 (03) : 1329 - 1362
  • [39] Information security threats and an easy-to-implement attack detection framework for wireless sensor network-based smart grid applications
    Tuna, G.
    Orenbas, H.
    Das, R.
    Kogias, D.
    Baykara, M.
    Gulez, K.
    [J]. 5TH INTERNATIONAL CONFERENCE ON MATERIALS AND APPLICATIONS FOR SENSORS AND TRANSDUCERS (IC-MAST2015), 2016, 108
  • [40] An Optimized Deep Learning Based Security Enhancement and Attack Detection on IoT Using IDS and KH-AES for Smart Cities
    Duraisamy, Ayyer
    Subramaniam, Muthusamy
    Rene Robin, Chinnanadar Ramachandran
    [J]. STUDIES IN INFORMATICS AND CONTROL, 2021, 30 (02): : 121 - 131