کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
551038 1450775 2015 17 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Current state of research on cross-site scripting (XSS) – A systematic literature review
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر تعامل انسان و کامپیوتر
پیش نمایش صفحه اول مقاله
Current state of research on cross-site scripting (XSS) – A systematic literature review
چکیده انگلیسی

ContextCross-site scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications.ObjectiveTo conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks.MethodWe followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to cross-site scripting from various journals and conference proceedings.ResultsResearch on XSS is still very active with publications across many conference proceedings and journals. Attack prevention and vulnerability detection are the areas focused on by most of the studies. Dynamic analysis techniques form the majority among the solutions proposed by the various studies. The type of XSS addressed the most is reflected XSS.ConclusionXSS still remains a big problem for web applications, despite the bulk of solutions provided so far. There is no single solution that can effectively mitigate XSS attacks. More research is needed in the area of vulnerability removal from the source code of the applications before deployment.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Information and Software Technology - Volume 58, February 2015, Pages 170–186
نویسندگان
, , , ,