Title
XSS-secure as a service for the platforms of online social network-based multimedia web applications in cloud.
Abstract
This article presents a novel framework XSS-Secure, which detects and alleviates the propagation of Cross-Site Scripting (XSS) worms from the Online Social Network (OSN)-based multimedia web applications on the cloud environment. It operates in two modes: training and detection mode. The former mode sanitizes the extracted untrusted variables of JavaScript code in a context-aware manner. This mode stores such sanitized code in sanitizer snapshot repository and OSN web server for further instrumentation in the detection mode. The detection mode compares the sanitized HTTP response (HRES) generated at the OSN web server with the sanitized response stored at the sanitizer snapshot repository. Any variation observed in this HRES message will indicate the injection of XSS worms from the remote OSN servers. XSS-Secure determines the context of such worms, perform the context-aware sanitization on them and finally sanitized HRES is transmitted to the OSN user. The prototype of our framework was developed in Java and integrated its components on the virtual machines of cloud environment. The detection and alleviation capability of our cloud-based framework was tested on the platforms of real world multimedia-based web applications including the OSN-based Web applications. Experimental outcomes reveal that our framework is capable enough to mitigate the dissemination of XSS worm from the platforms of non-OSN Web applications as well as OSN web sites with acceptable false negative and false positive rate.
Year
DOI
Venue
2018
10.1007/s11042-016-3735-1
Multimedia Tools Appl.
Keywords
Field
DocType
Cloud security, Cross-site scripting (XSS) worms, Online social networking (OSN) security, Web security, JavaScript code injection attacks, Sanitization routines
Computer science,Server,Cloud computing security,Cross-site scripting,Web application,Multimedia,Web server,JavaScript,Scripting language,Cloud computing
Journal
Volume
Issue
ISSN
77
4
1573-7721
Citations 
PageRank 
References 
20
0.62
15
Authors
2
Name
Order
Citations
PageRank
shashank gupta1848.88
Brij Bhooshan Gupta21569.95