The Experts below are selected from a list of 2871 Experts worldwide ranked by ideXlab platform
Novia Admodisastro - One of the best experts on this subject based on the ideXlab platform.
-
Towards Cross-Site Scripting Vulnerability Detection in Mobile Web Applications
International journal of engineering and technology, 2018Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Cross-Site Scripting vulnerabilities are among the top ten security vulnerabilities affecting web applications for the past decade and mobile version web applications more recently. They can cause serious problems for web users such as loss of personal information to web attackers, including financial and health information, denial of service attacks, and exposure to malware and viruses. Most of the proposed solutions focused only on the Desktop versions of web applications and overlooked the mobile versions. Increasing use of mobile phones to access web applications increases the threat of Cross-Site Scripting attacks on mobile phones. This paper presents work in progress on detecting Cross-Site Scripting vulnerabilities in mobile versions of web applications. It proposes an enhanced genetic algorithm-based approach that detects Cross-Site Scripting vulnerabilities in mobile versions of web applications. This approach has been used in our previous work and successfully detected the said vulnerabilities in Desktop web applications. It has been enhanced and is currently being tested in mobile versions of web applications. Preliminary results have indicated success in the mobile versions of web applications also. This approach will enable web developers find Cross-Site Scripting vulnerabilities in the mobile versions of their web applications before their release.
-
Cross-Site Scripting Detection Based on an Enhanced Genetic Algorithm
Indian journal of science and technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Software security vulnerabilities have led to many successful attacks on applications, especially web applications, on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to mitigate. Many solutions have been proposed for their detection. However, the problem of Cross-Site Scripting vulnerabilities present in web applications still persists. In this paper, we propose to explore an approach based on genetic algorithms that will be able to detect Cross-Site Scripting vulnerabilities in the source code before an application is deployed. The proposed approach is, so far, only implemented and validated on Java-based web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluations have indicated promising results.
-
Removing Cross-Site Scripting Vulnerabilities from Web Applications using the OWASP ESAPI Security Guidelines
Indian journal of science and technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to eliminate. Most solutions provided only focus on preventing attacks or detecting the vulnerabilities. Very few research works have addressed eliminating these vulnerabilities from the web applications source codes. In this paper, we propose an approach to remove Cross-Site Scripting vulnerabilities from the source code before an application is deployed. We make use of the OWASP Cross-Site Scripting prevention rules as guideline in our approach. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluation results have indicated promising results.
-
Current state of research on Cross-Site Scripting (XSS) – A systematic literature review
Information & Software Technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Context: Cross-Site Scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications. Objective: To conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks. Method: We followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to Cross-Site Scripting from various journals and conference proceedings. Results: Research on XSS is still very active with publications across many conference proceedings and journals. Attack prevention and vulnerability detection are the areas focused on by most of the studies. Dynamic analysis techniques form the majority among the solutions proposed by the various studies. The type of XSS addressed the most is reflected XSS. Conclusion: XSS still remains a big problem for web applications, despite the bulk of solutions provided so far. There is no single solution that can effectively mitigate XSS attacks. More research is needed in the area of vulnerability removal from the source code of the applications before deployment.
-
An approach for Cross-Site Scripting detection and removal based on genetic algorithms.
2014Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Abstract – Software security vulnerabilities have led to many successful attacks on applications, especially web applications, on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to eliminate. Many solutions have been proposed for their detection. However, the problem of Cross-Site Scripting vulnerabilities present in web applications still persists. In this paper, we propose to explore an approach based on genetic algorithms that will be able to detect and remove Cross-Site Scripting vulnerabilities from the source code before an application is deployed. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluations have indicated promising results.
Isatou Hydara - One of the best experts on this subject based on the ideXlab platform.
-
Towards Cross-Site Scripting Vulnerability Detection in Mobile Web Applications
International journal of engineering and technology, 2018Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Cross-Site Scripting vulnerabilities are among the top ten security vulnerabilities affecting web applications for the past decade and mobile version web applications more recently. They can cause serious problems for web users such as loss of personal information to web attackers, including financial and health information, denial of service attacks, and exposure to malware and viruses. Most of the proposed solutions focused only on the Desktop versions of web applications and overlooked the mobile versions. Increasing use of mobile phones to access web applications increases the threat of Cross-Site Scripting attacks on mobile phones. This paper presents work in progress on detecting Cross-Site Scripting vulnerabilities in mobile versions of web applications. It proposes an enhanced genetic algorithm-based approach that detects Cross-Site Scripting vulnerabilities in mobile versions of web applications. This approach has been used in our previous work and successfully detected the said vulnerabilities in Desktop web applications. It has been enhanced and is currently being tested in mobile versions of web applications. Preliminary results have indicated success in the mobile versions of web applications also. This approach will enable web developers find Cross-Site Scripting vulnerabilities in the mobile versions of their web applications before their release.
-
Cross-Site Scripting Detection Based on an Enhanced Genetic Algorithm
Indian journal of science and technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Software security vulnerabilities have led to many successful attacks on applications, especially web applications, on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to mitigate. Many solutions have been proposed for their detection. However, the problem of Cross-Site Scripting vulnerabilities present in web applications still persists. In this paper, we propose to explore an approach based on genetic algorithms that will be able to detect Cross-Site Scripting vulnerabilities in the source code before an application is deployed. The proposed approach is, so far, only implemented and validated on Java-based web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluations have indicated promising results.
-
Removing Cross-Site Scripting Vulnerabilities from Web Applications using the OWASP ESAPI Security Guidelines
Indian journal of science and technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to eliminate. Most solutions provided only focus on preventing attacks or detecting the vulnerabilities. Very few research works have addressed eliminating these vulnerabilities from the web applications source codes. In this paper, we propose an approach to remove Cross-Site Scripting vulnerabilities from the source code before an application is deployed. We make use of the OWASP Cross-Site Scripting prevention rules as guideline in our approach. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluation results have indicated promising results.
-
Current state of research on Cross-Site Scripting (XSS) – A systematic literature review
Information & Software Technology, 2015Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Context: Cross-Site Scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications. Objective: To conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks. Method: We followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to Cross-Site Scripting from various journals and conference proceedings. Results: Research on XSS is still very active with publications across many conference proceedings and journals. Attack prevention and vulnerability detection are the areas focused on by most of the studies. Dynamic analysis techniques form the majority among the solutions proposed by the various studies. The type of XSS addressed the most is reflected XSS. Conclusion: XSS still remains a big problem for web applications, despite the bulk of solutions provided so far. There is no single solution that can effectively mitigate XSS attacks. More research is needed in the area of vulnerability removal from the source code of the applications before deployment.
-
An approach for Cross-Site Scripting detection and removal based on genetic algorithms.
2014Co-Authors: Isatou Hydara, Abu Bakar Sultan, Hazura Zulzalil, Novia AdmodisastroAbstract:Abstract – Software security vulnerabilities have led to many successful attacks on applications, especially web applications, on a daily basis. These attacks, including Cross-Site Scripting, have caused damages for both web site owners and users. Cross-Site Scripting vulnerabilities are easy to exploit but difficult to eliminate. Many solutions have been proposed for their detection. However, the problem of Cross-Site Scripting vulnerabilities present in web applications still persists. In this paper, we propose to explore an approach based on genetic algorithms that will be able to detect and remove Cross-Site Scripting vulnerabilities from the source code before an application is deployed. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluations have indicated promising results.
Eduardo Feitosa - One of the best experts on this subject based on the ideXlab platform.
-
Automatic classification of Cross-Site Scripting in web pages using document-based and URL-based features
2012 IEEE Symposium on Computers and Communications (ISCC), 2012Co-Authors: Angelo Eduardo Nunan, Eduardo Souto, Eulanda Dos M. Santos, Eduardo FeitosaAbstract:The structure of dynamic websites comprised of a set of objects such as HTML tags, script functions, hyperlinks and advanced features in browsers lead to numerous resources and interactiveness in services currently provided on the Internet. However, these features have also increased security risks and attacks since they allow malicious codes injection or XSS (Cross-Site Scripting). XSS remains at the top of the lists of the greatest threats to web applications in recent years. This paper presents the experimental results obtained on XSS automatic classification in web pages using Machine Learning techniques. We focus on features extracted from web document content and URL. Our results demonstrate that the proposed features lead to highly accurate classification of malicious page.
M. Ponnavaikko - One of the best experts on this subject based on the ideXlab platform.
-
ACIS-ICIS - A solution to block Cross Site Scripting Vulnerabilities based on Service Oriented Architecture
6th IEEE ACIS International Conference on Computer and Information Science (ICIS 2007), 2007Co-Authors: Jayamsakthi Shanmugam, M. PonnavaikkoAbstract:Research data shows that, about 80% of the web applications are vulnerable to cross site Scripting attacks. This is because of the fact that the users are allowed to enter tags in the input control for increasing the flexibility in handling web applications input. This increases the threat to the web application by allowing the hackers to plant worms in the web applications through the features like tags. Further, there are billions of web pages that are developed in different languages like PHP, ASP, JSP, HTML, CGI- PERL, .Net etc. There is no single solution available that can be applied for the web application to prevent XSS that are developed in different languages and deployed in different platforms. This paper presents a new solution to block cross site Scripting (XSS) attacks that is independent of the languages in which the web applications are developed and addresses XSS vulnerabilities arise from other interfaces. The solution is modularized, configured, and developed in .Net, XML and XSD. This approach is evaluated in a web application developed in JSP/Servlets deployed in JBOSS application server and is found effective as it provides the flexibility to be used across languages with a very minimal configuration to prevent XSS.
-
a solution to block cross site Scripting vulnerabilities based on service oriented architecture
Annual ACIS International Conference on Computer and Information Science, 2007Co-Authors: Jayamsakthi Shanmugam, M. PonnavaikkoAbstract:Research data shows that, about 80% of the web applications are vulnerable to cross site Scripting attacks. This is because of the fact that the users are allowed to enter tags in the input control for increasing the flexibility in handling web applications input. This increases the threat to the web application by allowing the hackers to plant worms in the web applications through the features like tags. Further, there are billions of web pages that are developed in different languages like PHP, ASP, JSP, HTML, CGI- PERL, .Net etc. There is no single solution available that can be applied for the web application to prevent XSS that are developed in different languages and deployed in different platforms. This paper presents a new solution to block cross site Scripting (XSS) attacks that is independent of the languages in which the web applications are developed and addresses XSS vulnerabilities arise from other interfaces. The solution is modularized, configured, and developed in .Net, XML and XSD. This approach is evaluated in a web application developed in JSP/Servlets deployed in JBOSS application server and is found effective as it provides the flexibility to be used across languages with a very minimal configuration to prevent XSS.
-
Behavior-based anomaly detection on the server side to reduce the effectiveness of Cross Site Scripting vulnerabilities
3rd International Conference on Semantics, Knowledge, and Grid, SKG 2007, 2007Co-Authors: Jayamsakthi Shanmugam, M. PonnavaikkoAbstract:Cross-Site Scripting (XSS) is the top most vulnerability in the Web applications as mentioned by research groups. Every day new evasion mechanisms are found by the hackers due to new technology, new HTML tags and script functionalities introduced. Zero-day attacks exploit the vulnerability before the fix could be issued to protect the Web application users. This demands an efficient approach on the server side to protect the users of the application. The proposed behavior based anomaly detection approach introduces a security layer on top of the Web application, so that the existing Web application remain unchanged whenever a new threat is introduced that demands new security mechanisms. Further application level parameters are introduced to reduce the processing time.
S Yamaguchi - One of the best experts on this subject based on the ideXlab platform.
-
A proposal and implementation of automatic detection/collection system for Cross-Site Scripting vulnerability
18th International Conference on Advanced Information Networking and Applications 2004. AINA 2004., 2004Co-Authors: O. Ismail, M. Etoh, Youki Kadobayashi, S YamaguchiAbstract:Cross-Site Scripting (XSS) attacks target Web sites with cookie-based session management, resulting in the leakage of privacy information. Although several server-side countermeasures for XSS attacks do exist, such techniques have not been applied in a universal manner, because of their deployment overhead and the poor understanding of XSS problems. This paper proposes a client-side system that automatically detects XSS vulnerability by manipulating either request or server response. The system also shares the indication of vulnerability via a central repository. The purpose of the proposed system is twofold: to protect users from XSS attacks, and to warn the Web servers with XSS vulnerabilities.