Dissertation > Excellent graduate degree dissertation topics show

Research on Defense Techniques of Cross-Site Scripting Attack

Author: WuXiaoHeng
Tutor: LiJianHua
School: Shanghai Jiaotong University
Course: Communication and Information System
Keywords: Web security Cross-Site Scripting attack Defense system Self-healing
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 161
Quote: 0
Read: Download Dissertation

Abstract


Web 2.0 applications are very attractive to the developers and end-users, because they provide friendly interface, plenty of functions and high practicality. A significant feature of Web2.0 is that plenty of computing works and logical processing are carried out in the client side, by Client-side scripting technology such as JavaScript, VBscript, which brings a lot of convenience and ease of use, as well as potentially secure threats at the same time. At present, Cross-Side Scripting (XSS) is one of the most serious security problems in the Web. Its essential reason is the weakness in security mechanism of web application, that is, the lack of adequate inspection and filtering for the user‘s input. Report from WebCohort indicates that 80% web sites have the flaw of Cross-Side Scripting, and many large-scale web sites have been ever attacked because of such kind of vulnerability.This paper firstly studies deeply in cross-site scripting attack and treats of three kinds of cross-site scripting including reflected XSS, stored XSS and DOM-based XSS. Then it analyzes various kinds of the attack trigger mechanism, and also makes a summary about the way how Hackers rewrite the scripts to bypass the detection mechanism.After that, this paper designs a XSS defense system on the server side, which is comprised of the core engine, the management module and the database. The core engine, as the most essential part, consists of the pre-processing part, the detecting part, the output ?ltering part and the journal monitoring part. The pre-processing part is responsible for SSL decoding, encoding the input and normalization for the character set. And this part can achieve the goal of decoding HTTPS bit stream and prevent every mutation attack. The detecting part is designed to match the input with rules to detect XSS. The output ?ltering part can escape the special characters in untrusted content, thus completely eliminating the risk of unknown cross-site scripting attacks. But to some extent it will affect users’ experience. The journal part records all of the error messages, and adopts the hash function and message authentication code to achieve the integrity and consistency of the system for the convenience of further analysis and demonstration.By deploying the defense system in the reverse proxy server, we can protect the site from XSS attack without changing the existing Web server codes. The security vulnerabilities in different web sites cannot be totally the same.The system we design provides an operational solution to adpat these differences, which can help web sites prevent XSS attacks effectively. Meanwhile, the defense system will increase the response time.At last, traditional XSS defense method has a certain limitation. It just defenses the attack, but doesn’t make the best use of the detetion information to realize self-reparing. So this paper proposes a self-healing mechanism, which can help to automatically detect and fix the XSS vulnerability. We do some important reaserch on the mechanism including architecture, procedure, detect method and the exchange of flaw messages.

Related Dissertations

  1. Web Application Research on J2EE Multi-Layer Architecture,TP393.09
  2. TrojanAntier: A Statistical Analysis Based Web Trojan Defense System,TP393.08
  3. Toxic Effects of Copper, Cadmium, Cypermethrin and Deltamethrin Exposure on Tanichthys Albonubes Lin,X174
  4. The Litigation Right of Defense Counsel’s Protection in China,D925.2
  5. Dual leadership of our country 's air defense systems research,E256
  6. The Key Technologies Research of Web Application Security Development,TP393.08
  7. The Design and Implementation of Heterogeneous SDH Network Self-healing System Based on CORBA,TN914.332
  8. The Research and Implementation of Tunnel-AT Based on OSPF,TP393.04
  9. Research on Key Technologies for Asset Information Management System Based on .NET,TP311.52
  10. Research and Design of Queuing Strategy and Heartbeat Mechanism for Management Platform in Web Security Detection System,TP393.08
  11. Research on Application of Four-fiber Self-healing Rings in Electric Power Communication Networks,TN915.853
  12. Numerical Simulation of Self-healing System with Microcapsules,TB33
  13. The Study and Implementation of Grid System QoS Degradation Key Technologies Based on Organic Computing,TP393.09
  14. The Design and Implementation of Prevention Model of SQL Injection and XSS,TP393.08
  15. Research and Application of Web Security Vulnerability Detection System Base-on Grails,TP393.08
  16. On the separate sentencing procedure,D925.2
  17. Research on the Self-healing Capacity of Bitumen Mastics,U414
  18. Containing phyllosilicates wear self-healing agent antifriction properties,TB302
  19. Based on Set Pair Analysis Operational Effectiveness Evaluation of Air Defense System,E844
  20. Organophosphorus pesticides on amphipod River enjoys potter wasp toxic effects,X503.22
  21. Optimisation Design of Xingtai Tietong Local Telecommunications Network,TN919.3

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile