1ST Review
1ST Review
K.Anu Ranjani.
M.E. CSE
Reg no:1051617
OBJECTIVE
• Detects vulnerabilities in web applications that
are due to scripting attacks.
Reflected
Stored
DOM injection
REFERENCE PAPER -1
TITLE AUDITING THE DEFENSE AGAINST CROSS
SITE SCRIPTING IN WEB APPLICATIONS
AUTHOR Lwin Khin Shar and Hee Beng Kuan Tan
PUBLICATION
REFERENCE i) a novel approach for extracting XSS defense
features implemented in code to facilitate both
examination and auditing processes
ii) Livshits and Lam’s approach (Livshits and Lam,
2005).accounts for false positive rates did not
produce any false negative cases as assumed that a
complete vulnerability specification is provided by
user.
PUBLICATION
DISADVANTAGE
Degrade the performance of the web server.
• On client side, the most effective solution is to disable all
scripting language support in user’s browsers and e-mail readers.
DISADVANTAGES
Users will not be willing to disable all scripting language
support.
Users wont be keen to keep their browsers up to date.
Not reliable solutions as they depend on user’s configuration.
Cannot prevent newly introduced threat.
PROPOSED SYSTEM
ADVANTAGES
• Sound verification techniques for JSP web application
vulnerability analysis and vulnerability signature generation.
HARDWARE REQUIREMENTS: