loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Eighth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing (SNPD 2007)
XSS Application Worms: New Internet Infestation and Optimized Protective Measures
Haier International Training Center, Qingdao, China
July 30-August 01
ISBN: 0-7695-2909-7
M. Ponnavaikko, SRM University, Chennai
There has been considerable increase in Application layer attacks in the recent years. Research surveys show that the cross site scripting (XSS) attack is most common among all the application layer attacks. Ajax web technology, by design makes number of calls to the web server to process a user request. This increases the bandwidth usage and response time due increase in the number of calls to the web server. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the additional processing required thereby resulting in increased response time. If security mechanisms are implemented to protect the application, then the server performance will suffer due to the increased response time because of the increase in number of requests. This problem demands an efficient approach to protect the web application from XSS attacks and to block the malicious attempts from reaching the web application. This paper presents a thread based solution for efficient process utilization of the web server and to prevent XSS threats. The proposed solution has been tested using Java/JSP on JBOSS server on around 2000 vulnerable XSS input collected from various research sites, white hat and black hat sites. The model is also tested with the combination of non vulnerable input and vulnerable input to assess the performance. The approach is found to be effective compared to the earlier research works.
Index Terms:
Application-Level Web Security, Component-based Design, security vulnerabilities.
Citation:
Jayamsakthi Shanmugam, M. Ponnavaikko, "XSS Application Worms: New Internet Infestation and Optimized Protective Measures," snpd, vol. 3, pp.1164-1169, Eighth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing (SNPD 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.