18th International Conference on Advanced Information Networking and Applications (AINA'04) Volume 1
A Proposal and Implementation of Automatic Detection/Collection System for Cross-Site Scripting Vulnerability
Fukuoka, Japan
March 29-March 31
ISBN: 0-7695-2051-0
Omar Ismail, Nara Institute of Science and Technology, Ikoma, Nara
Masashi Etoh, Nara Institute of Science and Technology, Ikoma, Nara
Cross-site scripting (XSS) attacks target web sites with Cookie-based session management, resulting in the leakage of privacy information. Although several server-side countermeasures for XSS attacks do exist, such techniques have not been applied in a universal manner, because of their deployment overhead and the poor understanding of XSS problems. This paper proposes a client-side system that automatically detects XSS vulnerability by manipulating either request or server response. The system also shares the indication of vulnerability via a central repository. The purpose of the proposed system is twofold: to protect users from XSS attacks, and to warn the web servers with XSS vulnerabilities.
Citation:
Omar Ismail, Masashi Etoh, Youki Kadobayashi, Suguru Yamaguchi, "A Proposal and Implementation of Automatic Detection/Collection System for Cross-Site Scripting Vulnerability," aina, vol. 1, pp.145, 18th International Conference on Advanced Information Networking and Applications (AINA'04) Volume 1, 2004