![](/images/graphics-bg.png)
WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense
Joint Authors
Niakanlahiji, Amirreza
Jafarian, Jafar Haadi
Source
Security and Communication Networks
Issue
Vol. 2019, Issue 2019 (31 Dec. 2019), pp.1-13, 13 p.
Publisher
Hindawi Publishing Corporation
Publication Date
2019-05-14
Country of Publication
Egypt
No. of Pages
13
Main Subjects
Information Technology and Computer Science
Abstract EN
Existing mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers.
They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility.
Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning.
This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers.
In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications.
Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification.
Through rigorous evaluation, we show that WebMTD has very a low performance overhead.
Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead.
American Psychological Association (APA)
Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. 2019. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294
Modern Language Association (MLA)
Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks No. 2019 (2019), pp.1-13.
https://search.emarefa.net/detail/BIM-1210294
American Medical Association (AMA)
Niakanlahiji, Amirreza& Jafarian, Jafar Haadi. WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-13.
https://search.emarefa.net/detail/BIM-1210294
Data Type
Journal Articles
Language
English
Notes
Includes bibliographical references
Record ID
BIM-1210294