A systematic literature review on the characteristics and effectiveness of web application vulnerability scanners

S Alazmi, DC De Leon - IEEE Access, 2022 - ieeexplore.ieee.org
Web applications have been a significant target for successful security breaches in the last
few years. They are currently secured, as a primary method, by searching for their …

Twenty-two years since revealing cross-site scripting attacks: a systematic map** and a comprehensive survey

A Hannousse, S Yahiouche, MC Nait-Hamoud - Computer Science Review, 2024 - Elsevier
Cross-site scripting (XSS) is one of the major threats menacing the privacy of data and the
navigation of trusted web applications. Since its disclosure in late 1999 by Microsoft security …

A survey of exploitation and detection methods of XSS vulnerabilities

M Liu, B Zhang, W Chen, X Zhang - IEEE access, 2019 - ieeexplore.ieee.org
As web applications become more prevalent, web security becomes more and more
important. Cross-site scripting vulnerability abbreviated as XSS is a kind of common …

XSS adversarial example attacks based on deep reinforcement learning

L Chen, C Tang, J He, H Zhao, X Lan, T Li - Computers & Security, 2022 - Elsevier
Cross-site scripting (XSS) attack is one of the most serious security problems in web
applications. Although deep neural network (DNN) has been used in XSS attack detection …

Database traffic interception for graybox detection of stored and context-sensitive XSS

A Steinhauser, P Tůma - Digital Threats: Research and Practice, 2020 - dl.acm.org
Cross site scripting (XSS) is a type of a security vulnerability that permits injecting malicious
code into the client side of a web application. In the simplest situations, XSS vulnerabilities …

The impact of defensive programming on i/o cybersecurity attacks

JK Teto, R Bearden, DCT Lo - Proceedings of the SouthEast Conference, 2017 - dl.acm.org
This paper presents principles of Defensive Programming and examines the growing
concern that these principles are not effectively incorporated into Computer Science and …

A Review on detection of cross-site scripting attacks (XSS) in web security

JM Gan, HY Ling, YB Leau - … , ACeS 2020, Penang, Malaysia, December 8 …, 2021 - Springer
Cybersecurity is one of the pillars of the growth of the digital industry, Industry Revolution
4.0. The network universe has several forms of cyber threats. Web application is the most …

Adapting Static Taint Analyzers to Software Marketplaces: A Leverage Point for Mass Vulnerability Detection?

D Krohmer, K Sharma, S Chen - … of the 2022 ACM Workshop on Software …, 2022 - dl.acm.org
Improper input validation is still one of the most severe problem classes in web application
security, although there are concepts with a good problem-solution fit, such as static taint …

DjangoChecker: Applying extended taint tracking and server side parsing for detection of context‐sensitive XSS flaws

A Steinhauser, P Tůma - Software: Practice and Experience, 2019 - Wiley Online Library
Cross‐site scripting (XSS) flaws are a class of security flaws that permit the injection of
malicious code into a web application. In simple situations, these flaws can be caused by …

Maybe tainted data: Theory and a case study

C Skalka, S Amir-Mohammadian… - Journal of Computer …, 2020 - content.iospress.com
Dynamic taint analysis is often used as a defense against low-integrity data in applications
with untrusted user interfaces. An important example is defense against XSS and injection …