|国家预印本平台
首页|基于正则匹配的新型跨站脚本攻击的检测方案

基于正则匹配的新型跨站脚本攻击的检测方案

new detection method of cross site scripting attack base on regular matching

中文摘要英文摘要

随着网络的发展,信息安全显得日益重要,跨站脚本攻击一直是排名前三的网络威胁之一。随着HTML5的出现,跨站脚本攻击的形式也变得越来越复杂,在以往的检测策略中对新型的攻击向量检测不够完整以及对多层嵌套攻击向量也没有很好的检测手段,为了能够对新型的攻击向量进行检测,本文提出了一种基于正则表达式的检测算法,该算法对HTML5中新出现的特征进行分析,将跨站脚本攻击向量的攻击模式进行要素划分,采用了层次遍历的方法对多层嵌套攻击向量的出发点进行提取检测,最后加入了威胁领域知识对跨站脚本的数据源进行判断。实验证明,该算法能够达到很高的准确率和覆盖率以及较低的漏报率。

With the development of network, information security is becoming more and more important. Cross site scripting attack is one of the top three network threats. With the emergence of HTML5, the form of cross site scripting attacks has become more and more complex. In the past detection strategies, the detection of new attack vectors is not perfect. And there is no good detection method for multi-layer nested attack vector. In order to detect the new attack vector, this paper proposes a detection algorithm based on regular expression. The algorithm analyzes the new features in HTML5, divides the attack pattern of cross site script attack vector into elements, uses the hierarchical traversal method to extract and detectResearch on new detection method of cross site scripting attack the trigger points of multi-layer nested attack vector, and finally adds the threat domain knowledge To judge the data source of cross site script. Experimental results show that the algorithm can achieve high accuracy and coverage rate, as well as low missing report rate.

徐泽昊、李吉帅、崔栋、秦素娟

计算技术、计算机技术

信息安全跨站脚本攻击HTML5多层嵌套威胁领域知识

Information securitycross site scripting attackHTML5multilayer nestingthreat domain knowledge

徐泽昊,李吉帅,崔栋,秦素娟.基于正则匹配的新型跨站脚本攻击的检测方案[EB/OL].(2021-03-04)[2025-08-02].http://www.paper.edu.cn/releasepaper/content/202103-48.点此复制

评论