N-Gram Tabanlı Tahmin Modeli ile XSS Saldırısı Algılama

Author:

ALAGHA Bilal1ORCID

Affiliation:

1. ESKİŞEHİR OSMANGAZİ ÜNİVERSİTESİ, MÜHENDİSLİK-MİMARLIK FAKÜLTESİ

Abstract

The increment developments in technology has empowered the web applications. Meanwhile, the existence of Cross-Site Scripting (XSS) vulnerabilities in web applications has become a concern for users. In spite of the numerous current detection approaches, attackers have been exploiting XSS vulnerabilities for years, causing harm to the internet users. In this paper, a text-mining based approach to detect XSS attacks in web applications is introduced. This approach is built to extract a set of features from a publicly available source code files, which are then used to build a prediction model. The findings include few comparisons between Word Tokenization and N-Gram in accuracy, time spend to build the model and AUC-ROC curve. The results show that N-Gram tokenization outperforms the Word Tokenization.

Publisher

Eskisehir Osmangazi University

Reference43 articles.

1. [1] Ying, M., Li, S. Q. 2016. CSP adoption: current status and future prospects. Security and Communication Networks, 9(17), 4557-4573.

2. [2] sucuri.net. 2022. Sucuri Security. sitecheck.sucuri.net.

3. [3] Hearst, M. A. 1999. Untangling text data mining. In Proceedings of the 37th Annual meeting of the Association for Computational Linguistics, pp. 3-10.

4. [4] Feldman, R., Dagan, I. 1995. Knowledge Discovery in Textual Databases (KDT). In KDD, Vol. 95, pp. 112-117.

5. [5] positive technologies. 2022. Threats and Vulnerabilities in Web Applications 2020–2021. www.ptsecurity.com/ww-en/analytics/web-vulnerabilities-2020-2021/

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3