Dissertation > Excellent graduate degree dissertation topics show
Research on Client-side Detection Method for Cross-Site Scripting Vulnerability and Attack
Author: GongYanLei
Tutor: SongMingQiu
School: Dalian University of Technology
Course: E-commerce and logistics management
Keywords: Cross-site scripting attacks Sequence matching Fuzzing
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 121
Quote: 0
Read: Download Dissertation
Abstract
|
In recent years, WEB vulnerability has become one of the Internet's most serious security risks. Caused by the vulnerability WEB injection attacks are numerous cases, repeated. Cross-site scripting attacks it is this type of injection attacks affect the widest range, the influence of one of the deepest attack. Since 2006, cross-site scripting vulnerability has been ranked first in the WEB loopholes. Therefore, the detection and prevention of the design and development of an effective cross-site scripting attacks are particularly important. In this paper, on the basis of in-depth study of the characteristics of cross-site scripting attacks, and propose a new sequence-based matching cross-site scripting attack detection method, the method can effectively identify the parameter string variant form of server-side filtering function and discover missed detections. Part of the storage type for the algorithm can not detect cross-site scripting attacks, this paper proposes a detection method based on Fuzzing test. Finally, integration of design tools based on the two detection methods as a cross-site scripting vulnerabilities and attack detection system. The experiments show that the system can effectively detect out the the WEB network in the vast majority of cross-site scripting vulnerabilities and attacks. The main work of this paper include the following four parts: the first part of the analysis of the characteristics of cross-site scripting attacks, in-depth study of the problems of domestic and international cross-site scripting attack detection method as well as the current detection method and the future trends. The second and third part introduces this paper, the design of cross-site scripting attacks and vulnerability detection methods. The second part, a detailed description based on sequence match cross-site scripting attack detection methods, including HTTP request parameters match HTTP response the untrusted string information extraction and between the two parts. The method first user-supplied parameters abstract the form of a finite automaton to identify the sequence of the parameter string combination, then HTTP response untrusted string information and finite automata sequences match, looking for those that appear in the user input the untrusted string, request and server response check these strings malicious keywords and malicious URLs. The third part, the specific cross-site scripting vulnerability detection method based on Fuzzing test. First, by analyzing the characteristics of the site pages link, the structure is able to crawl the entire website page and efficient reptiles, the injection point of the page and then accurately identify and construct a malicious string injection test, and finally by identifying the response to mining cross-site scripting hole. Part IV describes the design and implementation of cross-site scripting detection system.
|
Related Dissertations
- Research of Fuzzing Based on Genetic Algorithm,TP311.53
- Automated Fuzz Testing network protocol vulnerabilities mining method,TP393.08
- Behavior-based cross-site scripting attack detection technology research and implementation,TP393.08
- Research and Implementation of the Web Vulnerability Detection System for Web Security,TP393.08
- The Research of XSS Detection and Defense Based Server-Client Cooperation,TP393.08
- Studies on Slurrying Characteristics and Improving That of Shenhua Coal Water Slurry,TQ536
- The Research and Implementation of the Attacking and Defencing Technology on the Database System,TP393.08
- Cross-site scripting attacks and defense technology research,TP393.08
- Research on Techniques of Exploiting IE Controls Vulnerabilities Based on Fuzzing,TP393.092
- Memory-based data mining fuzzing mechanisms of vulnerability,TP393.08
- Subsequence Matching Based Compressed XML Query,TP311.135.4
- Research on Technologies of Vulnerability Discovery Based upon Fuzzing and Bufferoverflow Vulnerability Exploitation,TP393.08
- Mechanism and Fuzzing Judge of Ash Slagging on Refractory Lined on Water-wall of Coal-fired Boilers,TK227
- Design and Implementation of Code Clone Analysis System Based on Sequence Matching,TP311.52
- Study on Vulnerability Discovery Technique Against Smart-phone,TP393.08
- Based on Time Series Similarity Matching Algorithm for Earthquake Prediction Research,P315.75
- Research on Software Security Vulnerability Discovery Based on Fuzzing,TP311.53
- The Research and Program Development for the Hydrolic Design of Bridges and Culvers,U442.3
- A Scene Matching Approach Based on Edge Signal between IR and Visible Images,TP391.41
- Research on Comprehensive Quality Evaluation of Cotton and Quality Predication for Colored Yorn,TS111
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|