2022 International Conference on Computer Communication and Informatics (ICCCI) · 2022 · 19 citations · 11 references
The global nature of web applications puts them at a high risk of attacks from different locations and with various levels of severity and complexity. Cross-Site Scripting (XSS) is a code injection attack that happens at the client-side i.e., through the web browsers. The attacker's main strategy is to execute the malicious injected scripts in a legitimate web application through the victim's browser. XSS vulnerabilities can be a source of other security attacks such as the spread of malware, credential theft, credential phishing, social network worms, and website defacing. Plenty of research has been carried out on the detection and prevention of XSS using machine learning techniques that involved URL-based features, HTML features, and JavaScript features and achieved an accuracy of about 98%. XSS attacks can have different forms and evolve regularly, new patterns emerge daily, feature extraction can be challenging, so there is a high probability of being not exhaustive. A Convolutional Neural network can be useful for XSS classification tasks, as because of its architecture it requires less feature extraction pre-processing task. In this paper, we used almost all the characters of XSS Scripts during feature generation and used the Convolutional Neural Network (CNN) technique to classify and detect the XSS scripts as malicious or benign and achieved the accuracy of 98.62 and precision of 98.6 and recall 98.86.
11
Efficient Malicious Code Detection Using N-Gram Analysis and SVM
Junho Choi, Hayoung Kim, Chang Choi et al. · 2011 · 69 citations