WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense

المؤلفون المشاركون

Niakanlahiji, Amirreza
Jafarian, Jafar Haadi

المصدر

Security and Communication Networks

العدد

المجلد 2019، العدد 2019 (31 ديسمبر/كانون الأول 2019)، ص ص. 1-13، 13ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2019-05-14

دولة النشر

مصر

عدد الصفحات

13

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Existing mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers.

They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility.

Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning.

This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers.

In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications.

Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification.

Through rigorous evaluation, we show that WebMTD has very a low performance overhead.

Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. 2019. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks No. 2019 (2019), pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1210294