Telecommunications Science ›› 2016, Vol. 32 ›› Issue (3): 87-91.doi: 10.11959/j.issn.1000-0801.2016068

• research and development • Previous Articles     Next Articles

A dynamic detection method based on Web crawler and page code behavior for XSS vulnerability

Yi LIU,Junbin HONG   

  1. Faculty of Computer,Guangdong University of Technology,Guangzhou 510006,China
  • Online:2016-03-20 Published:2016-03-28
  • Supported by:
    The National Natural Science Foundation of China;The Natural Science Foundation of Guangdong;The Science and Technology Planning Project of Guangdong Province;The Science and Technology Planning Project of Guangdong Province;The Science and Technology Planning Project of Guangzhou;The Science and Technology Planning Project of Guangzhou

Abstract:

XSS vulnerability is a common vulnerability of attacking the Web application and getting the user’s privacy data.Traditional XSS vulnerability detection’s softwares aren’t specially detecting for AJAX Web application.There is a huge disparity in the inspection accuracy.According to this situation,the XSS vulnerability characteristics of AJAX Web applications were described in detail,and a dynamic detection method based on Web crawler and page code behavior was proposed.Experimental results show that the proposed method has good performance in labor-saving,time saving and vulnerability detection effect.

Key words: XSS vulnerabilitiy, Web crawler, vulnerabilitiy detecting, AJAX Web application

No Suggested Reading articles found!