Watch What You Write: Preventing Cross-Site S cripting by Observing Program Output

msra(2008)

引用 24|浏览7
暂无评分
摘要
We introduce a dynamic technique for defending web appli- cations that would otherwise be vulnerable to cross-site scripting attacks. Our method is comprised of two phases: an attack-free training period where we capture the normal behavior of the application in the form of a set of likely program invariants, and an indefinite period of time spent in a potentially hostile environment where we check to make sure the appli- cation does not deviate from the normal behavior. We demonstrate that our approach is both effective at protecting vulnerable applications and capable of doing so without introducing a prohibitive amount of over- head. Our experiments suggest that this invariant-based technique is the most powerful and accurate automated mechanism for identifying and protecting against the widest range of cross-site scripting vulnerabilities.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要