Publication:
A multi-agent scanner to detect stored-XSS vulnerabilities

dc.affiliation.dptoUC3M. Departamento de Informáticaes
dc.affiliation.grupoinvUC3M. Grupo de Investigación: COSEC (Computer SECurity Lab)es
dc.contributor.authorGalán, Eduardo
dc.contributor.authorAlcaide Raya, Almudena
dc.contributor.authorOrfila Díaz-Pabon, Agustín
dc.contributor.authorBlasco Alís, Jorge
dc.date.accessioned2011-01-18T10:06:38Z
dc.date.available2011-01-18T10:06:38Z
dc.date.issued2010-11
dc.descriptionProceeding of: 2010 International Conference for Internet Technology and Secured Transactions (ICITST), 8 to 11 November 2010 London, England, United Kingdom
dc.description.abstractThe cross-site scripting (XSS) has become a common vulnerability of many web sites and web applications. XSS consists in the exploitation of input validation flaws, with the purpose of injecting arbitrary script code which is later executed at the web browser of the victim. One interesting possibility to prevent this type of vulnerability is the use of vulnerability scanners. However, current scanners are capable of detecting just one of the two main modalities of XSS attacks. This paper introduces a novel multi–agent system for the automated scanning of web sites to detect the presence of XSS vulnerabilities exploitable by an stored–XSS attack. The rate of detection of the system is evaluated in two different scenarios.
dc.description.sponsorshipThis work has been partially supported by CDTI (Ministerio de Industria, Turismo y Comercio of Spain) in collaboration with Telefonica I+D, Project SEGUR@ with reference CENIT-2007 2004
dc.description.statusPublicado
dc.format.mimetypeapplication/pdf
dc.identifier.bibliographicCitation2010 International Conference for Internet Technology and Secured Transactions (ICITST), pp 1-6
dc.identifier.isbn978-1-4244-8862-9
dc.identifier.publicationfirstpage1
dc.identifier.publicationlastpage6
dc.identifier.publicationtitle2010 International Conference for Internet Technology and Secured Transactions (ICITST)
dc.identifier.urihttps://hdl.handle.net/10016/9997
dc.language.isoeng
dc.publisherIEEE
dc.relation.eventdate8 to 11 November 2010
dc.relation.eventplaceLondon (England, United Kingdom)
dc.relation.eventtitle2010 International Conference for Internet Technology and Secured Transactions (ICITST)
dc.relation.publisherversionhttp://ieeexplore.ieee.org/search/srchabstract.jsp?tp=&arnumber=5678543&queryText%3DA+multi-agent+scanner+to+detect+stored-XSS+vulnerabilities%26openedRefinements%3D*%26filter%3DAND%28NOT%284283010803%29%29%26searchField%3DSearch+All
dc.rights© 2010 ICITST-2010 Technical Co-Sponsored by IEEE UK/RI Communications Chapter
dc.rights.accessRightsopen access
dc.subject.ecienciaInformática
dc.subject.otherMulti-agent
dc.subject.otherScanner
dc.subject.otherStored-XSS
dc.subject.otherXSS
dc.titleA multi-agent scanner to detect stored-XSS vulnerabilities
dc.typeconference paper*
dc.type.hasVersionVoR*
dspace.entity.typePublication
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
paper en proceedings 333-338.pdf
Size:
602.72 KB
Format:
Adobe Portable Document Format