IGXSS: XSS payload detection model based on inductive GCN

Author:

Wang Qiuhua12,Li Chuangchuang1,Wang Dong1,Yuan Lifeng1,Pan Gaoning1,Cheng Yanyu1,Hu Mingde1,Ren Yizhi1

Affiliation:

1. School of Cyberspace Hangzhou Dianzi University Hangzhou China

2. Data Security Governance Zhejiang Engineering Research Center Hangzhou Dianzi University Hangzhou China

Abstract

AbstractTo facilitate the management, Internet of Things (IoT) vendors usually apply remote ways such as HTTP services to uniformly manage IoT devices, leading to traditional web application vulnerabilities that also endanger the cloud interfaces of IoT, such as cross‐site scripting (XSS), code injection, and Remote Command/Code Execute (RCE). XSS is one of the most common web application attacks, which allows the attacker to obtain private user information or attack IoT devices and IoT cloud platforms. Most of the existing XSS payload detection models are based on machine learning or deep learning, which usually require a lot of external resources, such as pretrained word vectors, to achieve a better performance on unknown samples. But in the field of XSS payload detection, high‐quality vector representations of samples are often difficult to obtain. In addition, existing models all perform substantially worse when the distribution of XSS payloads and benign samples in the test dataset is extremely unbalanced (e.g., XSS payloads: benign samples = 1: 20). While in the real XSS attack scenario against IoT, an XSS payload is often hidden in a massive amount of normal user requests, indicating that these models are not practical. In response to the above issues, we propose an XSS payload detection model based on inductive graph neural networks, IGXSS (XSS payload detection model based on inductive GCN), to detect XSS payloads targeting IoT. Firstly, we treat the samples and words obtained from segmenting the samples as nodes and attach lines between them in order to form a graph. Then, we obtain the feature matrix of nodes and edges utilizing information between nodes only (instead of external resources such as pretrained word vectors). Finally, we feed the obtained feature matrix into a two‐layer GCN for training and validate the performance of models in several datasets with different sample distributions. Extensive experiments on the real datasets show that IGXSS performs better compared to other models under various sample distributions. In particular, when the sample distribution is extremely unbalanced, the recall and F1 score of IGXSS still reach 1.000 and 0.846, demonstrating that IGXSS is more robust and more suitable for practical scenarios.

Publisher

Wiley

Reference21 articles.

1. IoT‐Analytics.https://iot-analytics.com/reports-databases/.2022.

2. XSSClassifier: an efficient XSS attack detection approach based on machine learning classifier on SNSs;Rathore S;J Inf Process Syst,2017

3. XGBXSS: an extreme gradient boosting detection framework for cross‐site scripting attacks based on hybrid feature selection approach and parameters optimization;Mokbal FMM;J Inf Secur Appl,2021

4. GeneMiner: A Classification Approach for Detection of XSS Attacks on Web Services

5. Cross‐site scripting detection with two‐channel feature fusion embedded in self‐attention mechanism;Hu T;Comput Secur,2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3