Solving False Positive Problem in Client Side XSS Filter
Nitin Kumar Mishra, Saumya Chaturvedi, Chandrashekhar Dewangan, Sakshi Jain
Abstract
Nitin Kumar Mishra, Saumya Chaturvedi, Chandrashekhar Dewangan, Sakshi Jain
Abstract
Cross Site Scripting (XSS) is the most popular security problem in modern web application. In Cross Site Scripting, attacker uses a trusted site and injects a vulnerability script in the client or server side browser. This code when executes sends a secure information to attacker. This type of attack can be blocked by using server side filters and client side filters. In this work we have developed a two pass client side filter. This filter solves the well known problem of False Positive in various client side filters. We have proposed an architecture and algorithm that solves false positive problem.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Cross Site Scripting (XSS) is the most popular security problem in modern web application. In Cross Site Scripting, attacker uses a trusted site and injects a vulnerability script in the client or server side browser. This code when executes sends a secure information to attacker. This type of attack can be blocked by using server side filters and client side filters. In this work we have developed a two pass client side filter. This filter solves the well known problem of False Positive in various client side filters. We have proposed an architecture and algorithm that solves false positive problem.
Key concepts: Cross-site scripting, Client-side, Computer science, Server-side, Filter (signal processing), Computer security, Scripting language, Vulnerability (computing)