|国家预印本平台
首页|基于分布式跨站脚本漏洞检测技术的研究

基于分布式跨站脚本漏洞检测技术的研究

Research of Cross-Site Scripting Vulnerability Detection Technology

中文摘要英文摘要

在Web应用程序的众多攻击中, XSS攻击是最常见的安全隐患之一。本文针对跨站脚本漏洞检测准确率和效率低下的问题,提出了一种分布式的多线程动静态结合的跨站脚本漏洞检测的方案。该方案采用分布式架构,利用多线程网络爬虫算法查找定位XSS漏洞,再根据特定的XSS漏洞动态生成库攻击向量,然后利用该攻击向量库模拟攻击。这样可以全面快速地对网页进行跨站漏洞的检测。实验结果证明该方案具有一定的准确度,高效性和可扩展性,提高了检测效率,能够检测出更多的XSS漏洞。

mong the attacks on Web applications, XSS is one of the most common security risks. Against to the low accuracy and inefficient of those cross-site scripting vulnerability detection tool, this paper proposes a distributed multi-threaded static and dynamic binding cross-site scripting vulnerability detection program, which uses a distributed architecture, multi-threaded web crawler algorithm to find XSS vulnerabilities targeting and then dynamically generate the specific XSS vulnerabilities attack vector library, and then using this attack vector library simulated attack. This can comprehensive and quickly to conduct cross-site vulnerability detection on this web. The experimental results show that the proposed scheme has a certain degree of accuracy, efficiency and scalability, it improved the detection efficiency and can detect more XSS vulnerabilities.

杨君、马兆丰

计算技术、计算机技术

跨站脚本漏洞跨站脚本攻击跨站漏洞检测分布式爬虫网络安全

XSS vulnerabilityXSS attackXSS vulnerability detectiondistributed crawlernetwork security

杨君,马兆丰.基于分布式跨站脚本漏洞检测技术的研究[EB/OL].(2016-09-05)[2025-08-16].http://www.paper.edu.cn/releasepaper/content/201609-33.点此复制

评论