WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense

Joint Authors

Niakanlahiji, Amirreza
Jafarian, Jafar Haadi

Source

Security and Communication Networks

Issue

Vol. 2019, Issue 2019 (31 Dec. 2019), pp.1-13, 13 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2019-05-14

Country of Publication

Egypt

No. of Pages

13

Main Subjects

Information Technology and Computer Science

Abstract EN

Existing mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers.

They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility.

Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning.

This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers.

In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications.

Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification.

Through rigorous evaluation, we show that WebMTD has very a low performance overhead.

Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead.

American Psychological Association (APA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. 2019. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

Modern Language Association (MLA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks No. 2019 (2019), pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

American Medical Association (AMA)

Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1210294