Affiliation:
1. Department of IT, Indira Gandhi Delhi Technical University for Women, Delhi, India
Abstract
According to OWASP 2021, cross-site scripting (XSS) attacks are increasing through specially crafted XML documents. The attacker injects a malicious payload with a new pattern and combination of scripts, functions, and tags that deceits the existing security mechanisms in web services. This paper proposes an approach, GeneMiner, encompassing GeneMiner-E to extract new features and GeneMiner-C for classification of input payloads as malicious and nonmalicious. The proposed approach evolves itself to the changing patterns of attack payloads and identifies adversarial XSS attacks. The experiments have been conducted by collecting data from open source and generating various combinations of scripts, functions, and tags using an incremental genetic algorithm. The experimental results show that the proposed approach effectively detects newly crafted malicious XSS payloads with an accuracy of 98.5%, which is better than the existing classification techniques. The approach learns variations in the existing attack sample space and identifies the new attack payloads with reduced efforts.
Subject
General Mathematics,General Medicine,General Neuroscience,General Computer Science
Cited by
10 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Machine Learning-Driven Detection of Cross-Site Scripting Attacks;Information;2024-07-20
2. A Proactive Approach for Detecting SQL and XSS Injection Attacks;2024 3rd International Conference on Applied Artificial Intelligence and Computing (ICAAIC);2024-06-05
3. IGXSS: XSS payload detection model based on inductive GCN;International Journal of Network Management;2024-02-11
4. Research on intrusion detection based on Boyer-Moore pattern matching algorithm;Proceedings of the 2023 7th International Conference on Electronic Information Technology and Computer Engineering;2023-10-20
5. A Hybrid Dynamic Testing technology source code XSS vulnerability detection method;2023 IEEE Smart World Congress (SWC);2023-08-28