arrow
Return

Black-box adversarial attacks on XSS attack detection model

delete2022-02-01
delete18
PRE
AI
Q
Qiuhua Wang
H
Hui Yang
吴国华 (Guohua Wu)
K
Kim‐Kwang Raymond Choo
张政 cover
张政 (Zheng Zhang)
G
Gongxun Miao
Y
Yizhi Ren *
DOI:10.1016/j.cose.2021.102554delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Cross-site scripting (XSS) has been extensively studied, although mitigating such attacks in web applications remains challenging. While there is an increasing number of XSS attack detection approaches designed based on machine learning and deep learning algorithms, it is important to study and evaluate the reliability and security of these approaches. In our study, focusing on machine / deep learning-based XSS attack detection approaches, we propose a fuzzing-based approach to realize Black&White attack, in order to effectively improve the confidence coefficient of malicious samples. We also present an adversarial attack model based on Soft Q-learning, designed to generate adversarial attack examples for different XSS attack detection models using multiple strategies. Experimental results reveal that the proposed adversarial attack model generates adversarial attack examples against various XSS attack detection models, with an escape rate of over 85%. In other words, our research has implications on existing XSS attack detection models, for example in terms of effectiveness. (C) 2021 Elsevier Ltd. All rights reserved.
Keywords:
Cross-Site scripting
Adversarial attack examples
Black&white attack
Soft Q-learning

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

H
Hangzhou Dianzi University
Scholars:
1.3W
Papers: 9.6K
Citations: 7.5K
U
university of texas system
Scholars:
18.5W
Papers: 15.6W
Citations: 210