Vis enkel innførsel

dc.contributor.authorEllingsen, Pål
dc.contributor.authorVikne, Andreas Svardal
dc.date.accessioned2019-03-06T08:17:29Z
dc.date.available2019-03-06T08:17:29Z
dc.date.created2019-02-01T12:03:55Z
dc.date.issued2018
dc.identifier.citationEllingsen, P., & Vikne, A. S. (2018). Protecting against reflected cross-site scripting attacks. International Journal On Advances in Software, 11, 418-439.nb_NO
dc.identifier.issn1942-2628
dc.identifier.urihttp://hdl.handle.net/11250/2588920
dc.description.abstractOne of the most dominant threats against web applications is the class of script injection attacks, also called cross-site scripting. This class of attacks affects the client-side of a web application, and is a critical vulnerability that is difficult to both detect and remediate for websites, often leading to insufficient server-side protection, which is why the end-users need an extra layer of protection at the client-side, utilizing the defense in depth strategy. This paper discusses a client-side filter for Mozilla Firefox that protects against Reflected cross-site scripting attacks, while maintaining high performance. By conducting tests on the implemented solution, the conclusion is that the filter does provide more protection than the original Firefox version, at the same time achieving high performance, which with only some further improvements would become an effective option for end-users of web applications to protect themselves against Reflected cross-site scripting attacks.nb_NO
dc.language.isoengnb_NO
dc.relation.urihttp://www.iariajournals.org/software/soft_v11_n34_2018_paged.pdf
dc.rightsNavngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/deed.no*
dc.subjectcross-site scripting protectionnb_NO
dc.subjectinput filteringnb_NO
dc.subjectsoftware securitynb_NO
dc.subjectinjection attacksnb_NO
dc.titleProtecting Against Reflected Cross-Site Scripting Attacksnb_NO
dc.typeJournal articlenb_NO
dc.typePeer reviewednb_NO
dc.description.versionpublishedVersionnb_NO
dc.rights.holder2018, © Copyright by authors,nb_NO
dc.subject.nsiVDP::Matematikk og Naturvitenskap: 400::Informasjons- og kommunikasjonsvitenskap: 420::Sikkerhet og sårbarhet: 424nb_NO
dc.source.pagenumber418-439nb_NO
dc.source.volume11nb_NO
dc.source.journalInternational Journal On Advances in Softwarenb_NO
dc.source.issue3&4nb_NO
dc.identifier.cristin1672016
cristin.unitcode203,12,4,0
cristin.unitnameInstitutt for data- og realfag
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal