网络与信息安全学报 ›› 2018, Vol. 4 ›› Issue (11): 69-77.doi: 10.11959/j.issn.2096-109x.2018093

• 论文 • 上一篇    

面向规则缺陷的浏览器XSS过滤器测试方法

桂智杰1,2,舒辉1,2   

  1. 1 中国人民解放军信息工程大学网络空间安全学院,河南 郑州 450001
    2 数学工程与先进计算国家重点实验室,河南 郑州450001
  • 修回日期:2018-11-05 出版日期:2018-11-01 发布日期:2019-01-03
  • 作者简介:桂智杰(1996-),男,安徽马鞍山人,中国人民解放军信息工程大学硕士生,主要研究方向为软件漏洞挖掘与利用、逆向分析、嵌入式设备。|舒辉(1974-),男,江苏盐城人,中国人民解放军信息工程大学教授,主要研究方向为逆向工程。

Rule-defect oriented browser XSS filter test method

Zhijie GUI1,2,Hui SHU1,2   

  1. 1 School of Cyberspace Security,Information Support Engineering University of PLA,Zhengzhou 450001,China
    2 State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China
  • Revised:2018-11-05 Online:2018-11-01 Published:2019-01-03

摘要:

为了缓解跨站脚本(XSS,cross-site scripting)攻击,现代浏览器使用XSS过滤器进行防御,现有方法很难有效对浏览器XSS过滤器的安全性进行测试与评估。规则缺陷是浏览器XSS过滤器实现过程中的缺陷和安全问题。面向浏览器XSS过滤器规则缺陷,给出其形式化定义,设计测试样例和场景生成算法。为了定量测试与评估不同浏览器XSS过滤器的过滤水平,结合过滤成功率、误报率、输入损耗计算过滤能力。基于所提方法,设计原型系统对几种主流浏览器XSS过滤器进行自动化测试,得到了不同浏览器的XSS过滤能力。经过实际测试,该系统具备发现未公开漏洞的能力。

关键词: 跨站脚本攻击, 浏览器XSS过滤器, 规则缺陷, 过滤能力

Abstract:

In order to alleviate XSS (cross-site scripting) attacks,modern browsers use XSS filters for defense.It is difficult to effectively test and evaluate the security of browser XSS filters.The rule-defect is the defect and security problem in the implementation process of browser XSS filter.The formal definition,design test sample and scene generation algorithm were presented for browser XSS filter rule-defects.In order to quantitatively test and evaluate the filtering level of different browser XSS filters,combined with filtering success rate,false positive rate,input loss calculation filtering ability.Based on the proposed method,the prototype system is designed to automate the testing of several mainstream browser XSS filters,and the XSS filtering capabilities of different browsers are obtained.Further,after actual testing,the system also has the ability to discover undisclosed vulnerabilities.

Key words: cross-site scripting attack, browser XSS filter, rule-defect, filtering capabilitiy

中图分类号: 

No Suggested Reading articles found!