A DETECTION OF CROSS-SITE SCRIPTING ATTACK USING DYNAMIC ANALYSIS AND FUZZY INFERENCE SYSTEM (Record no. 5963)

000 -LEADER
fixed length control field 01803nam a22001457a 4500
008 - FIXED-LENGTH DATA ELEMENTS--GENERAL INFORMATION
fixed length control field 210802b ||||| |||| 00| 0 eng d
100 ## - MAIN ENTRY--AUTHOR
Author NTUK, Anderson Emmanuel
245 ## - TITLE STATEMENT
Title A DETECTION OF CROSS-SITE SCRIPTING ATTACK USING DYNAMIC ANALYSIS AND FUZZY INFERENCE SYSTEM
250 ## - SUPERVISOR
Supervisor Mr. O . J. Falana
260 ## - IMPRINT
Place of publication Ibafo
Department (College) Computer science and Mathematics
Date of publication 2019
300 ## - COLLATION
Pagination ix; 70
Other physical details dia, tables
520 ## - SUMMARY, ETC.
Summary, etc The rising population of security problems today’s Web applications is caused by injected<br/>codes, with cross-site scripting (XSS) attacks being the most common and dangerous web<br/>application attacks through the second millennium, with its drastic crumbling effect on popular<br/>sites like Facebook, Samsung, Apple, E-bay, Amazon etc. It is challenging for Web<br/>applications to completely eradicate the vulnerabilities because of its difficulty to properly<br/>sanitize all the user inputs sent to it. It is often the case that these vulnerabilities are not detected<br/>on time and fixed leaving users to be exposed to numerous attacks and thefts of personal<br/>information. This work discusses on the various XSS, its types, its detection and prevention<br/>mechanisms, and presents a detection framework built by a hybrid mechanism using Dynamic<br/>Analysis and Fuzzy Inference to detect these vulnerabilities in web applications for effective<br/>solutions to be met. Firstly, the detection systems scans website for discovering potential points<br/>for injections. Secondly, generates attack vectors and injects and is sent as HTTP request to<br/>web application. Lastly scans the HTTP response for presence of Attack vectors. Detection<br/>capability of our detection system is evaluated on real world web applications and desired<br/>results were obtained
650 ## - TRACINGS
Main Subject Computer Science
942 ## - ADDED ENTRY ELEMENTS (KOHA)
Item type Students Thesis
Holdings
Source of classification or shelving scheme Not for loan Permanent location Current location Shelving location Date acquired Accen. No. Koha item type
    Main Library Main Library Reference 02.08.2021 15010301023 Reference

Powered by Koha