XSSPro: XSS Attack Detection Proxy to Defend Social Networking Platforms

Pooja Chaudhary, B. B. Gupta, Chang Choi, Kwok Tai Chui

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Citations (Scopus)

Abstract

Social Platforms transpired as the fascinating attack surface to explode multitude of cyber-attacks as it facilitates sharing of personal and professional information. XSS vulnerability exists approximately in 80% of the social platforms. Hence, this paper presents an approach, XSSPro, to defend social networking platforms against XSS attacks. XSSPro operates through isolating the JavaScript code in the external file and performs decoding operation. The context of each injected JS code is identified and then similar scripts are grouped together to optimize the performance of XSSPro. Finally, extracted scripts are matched against the XSS attack vector repository to detect XSS attack. If matched then it is refined by using XSS APIs, otherwise, the response is XSS free and sent to the user. Experimental results revealed that XSSPro achieved an accuracy of 0.99 and is effective against thwarting XSS attack triggered using new features of the built-in code language with low false alarm rate.

Original languageEnglish
Title of host publicationComputational Data and Social Networks - 9th International Conference, CSoNet 2020, Proceedings
EditorsSriram Chellappan, Kim-Kwang Raymond Choo, NhatHai Phan
Pages411-422
Number of pages12
DOIs
Publication statusPublished - 2020
Event9th International Conference on Computational Data and Social Networks, CSoNet 2020 - Dallas, United States
Duration: 11 Dec 202013 Dec 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12575 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Conference on Computational Data and Social Networks, CSoNet 2020
Country/TerritoryUnited States
CityDallas
Period11/12/2013/12/20

Keywords

  • Code injection vulnerability
  • Cross site scripting (XSS)
  • Malicious JS code
  • Social networking platforms (SNPs)
  • XSS API

Fingerprint

Dive into the research topics of 'XSSPro: XSS Attack Detection Proxy to Defend Social Networking Platforms'. Together they form a unique fingerprint.

Cite this