• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

A Source Code Cross-site Scripting Vulnerability Detection Method


Abstract

To deal with the potential XSS vulnerabilities in the source code of the power communication network, an XSS vulnerability detection method combining the static analysis method with the dynamic testing method is proposed. The static analysis method aims to analyze the structure and content of the source code. We construct a set of feature expressions to match malignant content and set a "variable conversion" method to analyze the data flow of the code that implements interactive functions. The static analysis method explores the vulnerabilities existing in the source code structure and code content. Dynamic testing aims to simulate network attacks to reflect whether there are vulnerabilities in web pages. We construct many attack vectors and implemented the test in the Selenium tool. Due to the combination of the two analysis methods, XSS vulnerability discovery research could be conducted from two aspects: “white-box testing” and “black-box testing”. Tests show that this method can effectively detect XSS vulnerabilities in the source code of the power communication network.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
M. Chen, L. Chen, Z. Shao, Z. Dai, N. Li, X. Huang, Q. Dang, X. Zhao, "A Source Code Cross-site Scripting Vulnerability Detection Method," KSII Transactions on Internet and Information Systems, vol. 17, no. 6, pp. 1689-1705, 2023. DOI: 10.3837/tiis.2023.06.009.

[ACM Style]
Mu Chen, Lu Chen, Zhipeng Shao, Zaojian Dai, Nige Li, Xingjie Huang, Qian Dang, and Xinjian Zhao. 2023. A Source Code Cross-site Scripting Vulnerability Detection Method. KSII Transactions on Internet and Information Systems, 17, 6, (2023), 1689-1705. DOI: 10.3837/tiis.2023.06.009.

[BibTeX Style]
@article{tiis:50771, title="A Source Code Cross-site Scripting Vulnerability Detection Method", author="Mu Chen and Lu Chen and Zhipeng Shao and Zaojian Dai and Nige Li and Xingjie Huang and Qian Dang and Xinjian Zhao and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2023.06.009}, volume={17}, number={6}, year="2023", month={June}, pages={1689-1705}}