Twenty-two years since revealing cross-site scripting attacks: A systematic mapping and a comprehensive survey

计算机科学 脚本语言 跨站点脚本 万维网 数据科学 情报检索 程序设计语言 互联网 Web开发 Web应用程序安全性
作者
Abdelhakim Hannousse,Salima Yahiouche,Mohamed Cherif Nait-Hamoud
出处
期刊:Computer Science Review [Elsevier BV]
卷期号:52: 100634-100634 被引量:1
标识
DOI:10.1016/j.cosrev.2024.100634
摘要

Cross-site scripting (XSS) is one of the major threats menacing the privacy of data and the navigation of trusted web applications. Since its disclosure in late 1999 by Microsoft security engineers, several techniques have been developed with the aim of securing web navigation and protecting web applications against XSS attacks. XSS has been and is still in the top 10 list of web vulnerabilities reported by the Open Web Applications Security Project (OWASP). Consequently, handling XSS attacks has become one of the major concerns of several web security communities. Despite the numerous studies that have been conducted to combat XSS attacks, the attacks continue to rise. This motivates the study of how the interest in XSS attacks has evolved over the years, what has already been achieved to prevent these attacks, and what is missing to restrain their prevalence. In this paper, we conduct a systematic mapping and a comprehensive survey with the aim of answering all these questions. We summarize and categorize existing endeavors that aim to handle XSS attacks and develop XSS-free web applications. The systematic mapping yielded 157 high-quality published studies. By thoroughly analyzing those studies, a comprehensive taxonomy is drawn out outlining various techniques used to prevent, detect, protect, and defend against XSS attacks and vulnerabilities. The study of the literature revealed a remarkable interest bias toward basic (84.71%) and JavaScript (81.63%) XSS attacks as well as a dearth of vulnerability repair mechanisms and tools (only 1.48%). Notably, existing vulnerability detection techniques focus solely on single-page detection, overlooking flaws that may span across multiple pages. Furthermore, the study brought to the forefront the limitations and challenges of existing attack detection and defense techniques concerning machine learning and content-security policies. Consequently, we strongly advocate the development of more suitable detection and defense techniques, along with an increased focus on addressing XSS vulnerabilities through effective detection (hybrid solutions) and repair strategies. Additionally, there is a pressing need for more high-quality studies to overcome the limitations of promising approaches such as machine learning and content-security policies while also addressing diverse XSS attacks in different languages. Hopefully, this study can serve as guidance for both the academic and practitioner communities in the development of XSS-free web applications.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
谦让月饼完成签到 ,获得积分10
刚刚
lli完成签到,获得积分10
3秒前
3秒前
3秒前
wkf218416完成签到,获得积分10
4秒前
七濑发布了新的文献求助10
4秒前
5秒前
Akim应助弓箭手采纳,获得10
5秒前
Orange应助Yolo采纳,获得10
5秒前
星空发布了新的文献求助10
5秒前
梁成伟完成签到,获得积分10
7秒前
wkf218416发布了新的文献求助30
8秒前
9秒前
10秒前
郭郭9706发布了新的文献求助30
11秒前
13秒前
wumengke完成签到,获得积分10
14秒前
WizBLue发布了新的文献求助10
14秒前
乐乐应助科研通管家采纳,获得50
18秒前
Jasper应助科研通管家采纳,获得10
18秒前
彭于晏应助科研通管家采纳,获得10
18秒前
英俊的铭应助科研通管家采纳,获得10
18秒前
科研通AI5应助科研通管家采纳,获得10
18秒前
Akim应助科研通管家采纳,获得10
18秒前
斯文败类应助科研通管家采纳,获得10
18秒前
18秒前
ding应助科研通管家采纳,获得10
18秒前
18秒前
18秒前
顺心的皮卡丘完成签到 ,获得积分10
19秒前
张平一完成签到 ,获得积分10
24秒前
宝宝完成签到 ,获得积分20
25秒前
25秒前
26秒前
小饼干完成签到 ,获得积分10
26秒前
elmacho完成签到 ,获得积分10
28秒前
硕shuo发布了新的文献求助10
28秒前
烟花应助wswddtd采纳,获得10
29秒前
万能图书馆应助zmy采纳,获得10
31秒前
高分求助中
Applied Survey Data Analysis (第三版, 2025) 800
Assessing and Diagnosing Young Children with Neurodevelopmental Disorders (2nd Edition) 700
Images that translate 500
Algorithmic Mathematics in Machine Learning 500
Handbook of Innovations in Political Psychology 400
Mapping the Stars: Celebrity, Metonymy, and the Networked Politics of Identity 400
Nucleophilic substitution in azasydnone-modified dinitroanisoles 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3842690
求助须知:如何正确求助?哪些是违规求助? 3384714
关于积分的说明 10536898
捐赠科研通 3105250
什么是DOI,文献DOI怎么找? 1710164
邀请新用户注册赠送积分活动 823501
科研通“疑难数据库(出版商)”最低求助积分说明 774137