Efficient Prediction of Cross-Site Scripting Web Pages using Extreme Learning Machine

نویسنده

  • S. Krishnaveni
چکیده

Malicious code is a way of attempting to acquire sensitive information by sending malicious code to the trustworthy entity in an electronic communication. JavaScript is the most frequently used command language in the web page environment. If the hackers misuse the JavaScript code there is a possibility of stealing the authentication and confidential information about an organization and user. The attack is based on the malicious JavaScript code inserted into pages by intruders or hackers. Various attacks like redirect, script injection and XSS which usually include to transmitting private data to attacker or redirecting the victim to web content controlled by hacker. A cross-site scripting vulnerability allows the introduction of malicious content on a web site that is then served to users. Therefore filtering malicious JavaScript code is necessary for any web application. The aim of this work is to analyze different malicious code attacks phenomenon, various types of malicious code attacks. The experimental results obtained on XSS classification in web pages using Extreme Learning Machine techniques. ELM approach can be found in its high sparseness, it can also be seen that ELM accomplishes better and more balanced classification for individual categories as well in very less training time comparative to other classification algorithms. The data are collected from the real web pages and various features are extracted to classify the malicious web page using supervised learning algorithms and the results demonstrate that the proposed features lead to highly accurate classification of malicious page. Keywords— DOM-based attack, ELM, KELM, Malicious code, OWASP, Redirect attack, SOL injection attack, Web surfing, XSS.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Multiclass Classification of XSS Web Page Attack using Machine Learning Techniques

Web applications are most widely used technique for providing an access to online services. At the same time web applications are easiest way for vulnerable acts. When a security mechanism is failed then the user may download malicious code from a trusted web site. In this case, the malicious script is contracted to full access with all assets belonging to that legitimate web site. These types ...

متن کامل

Analyzing new features of infected web content in detection of malicious web pages

Recent improvements in web standards and technologies enable the attackers to hide and obfuscate infectious codes with new methods and thus escaping the security filters. In this paper, we study the application of machine learning techniques in detecting malicious web pages. In order to detect malicious web pages, we propose and analyze a novel set of features including HTML, JavaScript (jQuery...

متن کامل

An Execution-flow Based Method for Detecting Cross-Site Scripting of Ajax Applications

We present an execution-flow analysis for JavaScript programs running in a web browser to prevent Cross-site Scripting (XSS) attacks. We construct finite-state automata (FSA) to model the client-side behavior of Ajax applications under normal execution. Our system is deployed in proxy mode. The proxy analyzes the execution flow of client-side JavaScript before the requested web pages arrive at ...

متن کامل

A Server Side Solution for Protection of Web Applications from Cross-Site Scripting Attacks

Cross-Site scripting attacks occur when accessing information in intermediate trusted sites. Cross-Site Scripting (XSS) is one of the major problems of any Web application. Web browsers are used in the execution of commands in web pages to enable dynamic Web pages attackers to make use of this feature and to enforce the execution of malicious code in a user’s Web browser. This paper describes t...

متن کامل

Eradicating Cross Site Scripting Attack for a Secure Web Access

Recent updates of Vulnerability reports of the Open Web Application Security Project confirm that Cross Site Scripting (XSS) is one of the most common and severe web security defects. Cross-Site Scripting occurs when an application takes data from the user and sends it back to a web browser without validation or encoding. It occurs when the web application references the user input in HTML page...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013