Cross-Site Scripting (XSS) attacks are among the most exploited vulnerabilities in web applications. As a countermeasure, various open-source XSS detectors have been released over the years, but none of such tools has been significantly tested to verify their effectiveness. In this paper, we propose an assessment of five of the most employed XSS detectors in the wild. The purpose of this analysis is two-folded: (i) to understand their efficacy in well-known and customized vulnerable environments; (ii) to provide a better comprehension of their detection mechanisms. We performed our evaluation by testing the detectors against one publicly available test bench. Additionally, we created two customized test benches that contain less trivial XSS vulnerabilities. The attained results show how, while most detectors show good accuracy at detecting trivial XSS vulnerabilities, they could fail as the XSS complexity increases.

A Targeted Assessment of Cross-Site Scripting Detection Tools / Pala, B.; Pisu, L.; Sanna, S. L.; Maiorca, D.; Giacinto, G.. - 3488:(2023). ( 2023 Italian Conference on Cyber Security, ITASEC 2023 ita ).

A Targeted Assessment of Cross-Site Scripting Detection Tools

Pala B.;Pisu L.;Sanna S. L.;
2023

Abstract

Cross-Site Scripting (XSS) attacks are among the most exploited vulnerabilities in web applications. As a countermeasure, various open-source XSS detectors have been released over the years, but none of such tools has been significantly tested to verify their effectiveness. In this paper, we propose an assessment of five of the most employed XSS detectors in the wild. The purpose of this analysis is two-folded: (i) to understand their efficacy in well-known and customized vulnerable environments; (ii) to provide a better comprehension of their detection mechanisms. We performed our evaluation by testing the detectors against one publicly available test bench. Additionally, we created two customized test benches that contain less trivial XSS vulnerabilities. The attained results show how, while most detectors show good accuracy at detecting trivial XSS vulnerabilities, they could fail as the XSS complexity increases.
2023
2023 Italian Conference on Cyber Security, ITASEC 2023
Cross-Site Scripting; Exploitation; Web Security
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
A Targeted Assessment of Cross-Site Scripting Detection Tools / Pala, B.; Pisu, L.; Sanna, S. L.; Maiorca, D.; Giacinto, G.. - 3488:(2023). ( 2023 Italian Conference on Cyber Security, ITASEC 2023 ita ).
File allegati a questo prodotto
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1718953
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact