返回
XSS adversarial example attacks based on deep reinforcement learning
DOI:10.1016/j.cose.2022.102831.png)
摘要
En 中文
Cross-site scripting (XSS) attack is one of the most serious security problems in web applications. Although deep neural network (DNN) has been used in XSS attack detection and achieved unprecedented success, it is vulnerable to adversarial example attacks because its input-output mapping is quite discontinuous to a large extent. The existence of adversarial examples have raised concerns in applying deep learning to key security fields. Therefore, to evaluate the effectiveness of these detection methods, a XSS adversarial example attack technique using Soft Actor-Critic (SAC) reinforcement learning algorithm is presented in the paper. A key aspect of our idea is to train an agent using SAC algorithm to build adversarial examples for several popular XSS detection models which have been proved can achieve very high accuracy rate by simulation experiments. We first design mutation strategies for different modules of XSS attack vectors to ensure the validity of the generated adversarial examples. Then, the agent selects an appropriate escape strategy according to the feedback of the detection model until it bypasses the detection model. The final experiment results show that our model can achieve an escape rate of more than 92% and outperforms the latest method by up to 6%. In other words, the effectiveness of these detection models needs to be improved, at least in terms of defense adversarial example attacks. (C) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Web security
Cross site scripting
Adversarial examples
Adversarial attack
SAC
Reinforcement learning
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
A novel architecture for web-based attack detection using convolutional neural network
COMPUTERS & SECURITY
IF5.4
Adversarial Examples Detection for XSS Attacks Based on Generative Adversarial Networks基于生成对抗网络的XSS攻击对抗实例检测
IEEE ACCESS
IF3.6
Humorous cognitive reappraisal: More benign humour and less "dark" humour is affiliated with more adaptive cognitive reappraisal strategies
PLOS ONE
IF0
MLPXSS: An Integrated XSS-Based Attack Detection Scheme in Web Applications Using Multilayer Perceptron Technique
IEEE ACCESS
IF3.6
没有更多内容

