亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Twenty-two years since revealing cross-site scripting attacks: A systematic mapping and a comprehensive survey

计算机科学 脚本语言 跨站点脚本 万维网 数据科学 情报检索 程序设计语言 互联网 Web开发 Web应用程序安全性
作者
Abdelhakim Hannousse,Salima Yahiouche,Mohamed Cherif Nait-Hamoud
出处
期刊:Computer Science Review [Elsevier]
卷期号:52: 100634-100634 被引量:1
标识
DOI:10.1016/j.cosrev.2024.100634
摘要

Cross-site scripting (XSS) is one of the major threats menacing the privacy of data and the navigation of trusted web applications. Since its disclosure in late 1999 by Microsoft security engineers, several techniques have been developed with the aim of securing web navigation and protecting web applications against XSS attacks. XSS has been and is still in the top 10 list of web vulnerabilities reported by the Open Web Applications Security Project (OWASP). Consequently, handling XSS attacks has become one of the major concerns of several web security communities. Despite the numerous studies that have been conducted to combat XSS attacks, the attacks continue to rise. This motivates the study of how the interest in XSS attacks has evolved over the years, what has already been achieved to prevent these attacks, and what is missing to restrain their prevalence. In this paper, we conduct a systematic mapping and a comprehensive survey with the aim of answering all these questions. We summarize and categorize existing endeavors that aim to handle XSS attacks and develop XSS-free web applications. The systematic mapping yielded 157 high-quality published studies. By thoroughly analyzing those studies, a comprehensive taxonomy is drawn out outlining various techniques used to prevent, detect, protect, and defend against XSS attacks and vulnerabilities. The study of the literature revealed a remarkable interest bias toward basic (84.71%) and JavaScript (81.63%) XSS attacks as well as a dearth of vulnerability repair mechanisms and tools (only 1.48%). Notably, existing vulnerability detection techniques focus solely on single-page detection, overlooking flaws that may span across multiple pages. Furthermore, the study brought to the forefront the limitations and challenges of existing attack detection and defense techniques concerning machine learning and content-security policies. Consequently, we strongly advocate the development of more suitable detection and defense techniques, along with an increased focus on addressing XSS vulnerabilities through effective detection (hybrid solutions) and repair strategies. Additionally, there is a pressing need for more high-quality studies to overcome the limitations of promising approaches such as machine learning and content-security policies while also addressing diverse XSS attacks in different languages. Hopefully, this study can serve as guidance for both the academic and practitioner communities in the development of XSS-free web applications.

科研通智能强力驱动
Strongly Powered by AbleSci AI

祝大家在新的一年里科研腾飞
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
kazemi完成签到,获得积分10
1秒前
InsanityK发布了新的文献求助50
5秒前
jcksonzhj完成签到,获得积分10
20秒前
研友_VZG7GZ应助无限的妖妖采纳,获得10
22秒前
上官若男应助科研通管家采纳,获得50
23秒前
34秒前
暮然完成签到,获得积分10
43秒前
sylar发布了新的文献求助10
1分钟前
1分钟前
郭德久完成签到 ,获得积分0
1分钟前
热心妍发布了新的文献求助10
1分钟前
暴躁咩完成签到 ,获得积分10
1分钟前
柒姐完成签到,获得积分10
1分钟前
bkagyin应助Faria采纳,获得10
1分钟前
1分钟前
李健应助YOG采纳,获得10
1分钟前
1分钟前
7373完成签到 ,获得积分10
1分钟前
1分钟前
orangel完成签到,获得积分10
1分钟前
思柔完成签到,获得积分10
1分钟前
泪是雨的旋律完成签到 ,获得积分10
2分钟前
小马2023发布了新的文献求助10
2分钟前
2分钟前
2分钟前
2分钟前
Faria发布了新的文献求助10
2分钟前
YOG发布了新的文献求助10
2分钟前
2分钟前
nana发布了新的文献求助30
2分钟前
互助应助科研通管家采纳,获得10
2分钟前
愔愔应助科研通管家采纳,获得20
2分钟前
互助应助科研通管家采纳,获得10
2分钟前
852应助科研通管家采纳,获得10
2分钟前
Richard完成签到,获得积分10
2分钟前
JamesPei应助小马2023采纳,获得10
2分钟前
SGOM完成签到 ,获得积分10
2分钟前
flyinthesky完成签到,获得积分10
2分钟前
张晓祁完成签到,获得积分10
3分钟前
3分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Les Mantodea de guyane 2500
Signals, Systems, and Signal Processing 510
Discrete-Time Signals and Systems 510
《The Emergency Nursing High-Yield Guide》 (或简称为 Emergency Nursing High-Yield Essentials) 500
The Dance of Butch/Femme: The Complementarity and Autonomy of Lesbian Gender Identity 500
Differentiation Between Social Groups: Studies in the Social Psychology of Intergroup Relations 350
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5880512
求助须知:如何正确求助?哪些是违规求助? 6573473
关于积分的说明 15689941
捐赠科研通 5000219
什么是DOI,文献DOI怎么找? 2694223
邀请新用户注册赠送积分活动 1636089
关于科研通互助平台的介绍 1593468