A Hybrid Dynamic Testing technology source code XSS vulnerability detection method

Xubin Wang,Yuhua Xu,Zhixin Sun

2023 IEEE Smart World Congress (SWC)(2023)

引用 0|浏览0
暂无评分
摘要
Presently power network security attacks occur frequently, data security and privacy communication are facing a major threat, and secure data communication is imminent. Aiming at the injection attack type of Cross-site scripting attack(XSS), we analyze it and design a hybrid dynamic testing technology method. SVM is combined to build a discriminator to distinguish malignant scripts. Browser tools are used to simulate attacks and built-in script execution functions are used to continuously monitor the target attribute values and page status, dynamically discover malicious content, and improve source code security. Experiments show that this method is effective for vulnerability detection. It has low overhead in the process of implementing dynamic testing and effectively improves the accuracy of vulnerability analysis combined with static content analysis.
更多
查看译文
关键词
Cross-site scripting vulnerability,Dynamic testing,Selenium,SVM
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要