计算机科学 ›› 2018, Vol. 45 ›› Issue (11A): 356-360.
赵澄, 陈君新, 姚明海
ZHAO Cheng, CHEN Jun-xin, YAO Ming-hai
摘要: Web应用高速发展的同时产生了大量安全漏洞,跨站脚本攻击(XSS)就是危害最为严重的Web漏洞之一,而基于规则的传统XSS检测工具难以检测未知的和变形的XSS。为了应对未知的和变形的XSS,文中提出了一种基于支持向量机(SVM)分类器的XSS攻击检测方案。该方案在大量分析XSS攻击样本及其变形样本和正常样本的基础上,提取最具代表性的五维特征并将这些特征向量化,然后进行SVM算法的训练和测试。通过准确率、召回率和误报率3个指标来对分类器的检测效果进行评价,并优化特征提取方式。改进后的SVM分类器与传统工具和普通SVM相比性能均有所提升。
中图分类号:
[1]张伟,吴灏,邹郅路.针对基于编码的跨站脚本攻击分析及防范方法[J].小型微型计算机系统,2013,34(7):1615-1619. [2]SHASHANK G,GUPTA B B,POOJA C.Hunting for DOM-Based XSS vulnerabilities in mobile cloud-based online social network[J].Future Generation Computer Systems,2018,79(1):319-336. [3]WANG W,LIU J Q,PITSILIS G,et al.Abstracting massive data for lightweight intrusion detection in computer networks[J].Information Sciences,2018,433:417-430. [4]吴少华,程书宝,胡勇.基于SVM的Web攻击检测技术[J].计算机科学,2015,42(6A):362-364. [5]MAHMOOD M,ALI Y V.New rule-based phishing detection method[J].Expert Systems With Applications,2016,53:231-242. [6]SALAS M I P,MARTINS E.Security Testing Methodology for Vulnerabilities Detection of XSS in Web Services and WS-Securi-ty[J].Electronic Notes in Theoretical Computer Science,2014,302(302):133-154. [7]ADEVA J J G,ATXA J M P.Inrusion detection in web application using text mining[J].Engineering Applications of Artificial Intelligence,2007,20(4):555-566. [8]ROCHA T S,SOUTO E.ETSSDetector:A Tool to Automati-cally Detect Cross-Site Scripting Vulnerabilities[C]∥NetWork Computing and Applications.IEEE Computer Society,2014:306-309. [9]BISHT P,VENKATAKRISHNAN V N.XSS-GUARD:Precise Dynamic Prevention of Cross-Site Scripting Attacks[C]∥In Proceeding of Conference on Detection of Intrusions and Malware & Vulnerability Assessment.2008:23-43. [10]邱永华.XSS跨站脚本攻击剖析与防御[M].北京:人民邮电出版社,2013. [11]AHUSBORDE E,AZAIEZ M,BELGACEM F B,et al.Mercer’s spectral decomposition for the characterization of thermal parameters[J].Journal of Computational Physics,2015,294(C):1-19. |
[1] | 李梦荷, 许宏吉, 石磊鑫, 赵文杰, 李娟. 基于骨骼关键点检测的多人行为识别 Multi-person Activity Recognition Based on Bone Keypoints Detection 计算机科学, 2021, 48(4): 138-143. https://doi.org/10.11896/jsjkx.200300042 |
[2] | 李昆仑,张亚欣,刘利利,耿雪菲. 基于改进PCA和支持向量机的掌纹识别 Palmprint Recognition Based on Improved PCA and SVM 计算机科学, 2015, 42(Z11): 146-150. |
[3] | 申铉京,李梦臻,吕颖达,陈海鹏. 基于LBC的计算机生成图像盲鉴别算法 Blind Identification Algorithm of Photorealistic Computer Graphics Based on Local Binary Count 计算机科学, 2015, 42(6): 135-138. https://doi.org/10.11896/j.issn.1002-137X.2015.06.030 |
[4] | 刘纯利,张弓. 物体边沿特征提取及应用 Grain Classification Based on Edge Feature 计算机科学, 2013, 40(7): 280-282. |
[5] | 张永,薛芝茂. 基于两级分类器的人脸检测系统设计 Face Detection System Design Based on Two Classifiers 计算机科学, 2010, 37(4): 293-. |
|