A DETECTION OF CROSS-SITE SCRIPTING ATTACK USING DYNAMIC ANALYSIS AND FUZZY INFERENCE SYSTEM

Project Document Preview

CHAPTER ONE

INTRODUCTION

1.1 Background of Study

Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Cross-site scripting carried out on websites accounted for roughly 84% of all security vulnerabilities documented by Symantec as of 2007. Their effect may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner.

1.2 Statement of the Problem

Web applications are increasingly becoming the primary medium for delivering services and information. However, this growth has been accompanied by a corresponding rise in security threats, with cross-site scripting being one of the most prevalent and dangerous attacks. Existing detection methods often rely on static analysis or signature-based approaches, which are insufficient for detecting novel or obfuscated XSS attacks. Moreover, these methods often produce high false positive rates, leading to alert fatigue and reduced effectiveness. Therefore, there is a need for a more robust and accurate detection system that can identify XSS attacks in real-time while minimizing false positives.

1.3 Aim and Objectives of the Study

The aim of this study is to develop a detection system for cross-site scripting attacks using dynamic analysis and fuzzy inference system. The specific objectives are to:

i. Analyze existing XSS detection techniques and identify their limitations.

ii. Design a fuzzy inference system that can classify web requests as benign or malicious based on dynamic analysis features.

iii. Implement the proposed detection system using dynamic analysis and fuzzy inference.

iv. Evaluate the performance of the system in terms of detection accuracy, false positive rate, and processing time.

1.4 Significance of the Study

The significance of this study lies in its potential to enhance web application security by providing a more accurate and efficient method for detecting XSS attacks. The system will help reduce false positives, thereby improving the usability of security tools. Additionally, the findings will contribute to the body of knowledge in the field of web security and fuzzy logic applications.

1.5 Scope of the Study

The study focuses on detecting reflected and stored XSS attacks in web applications. It utilizes dynamic analysis to collect runtime data from web requests and responses. The fuzzy inference system is designed to evaluate the maliciousness of the requests. The system is tested on a local web application environment and evaluated using standard metrics. The study does not cover other types of web attacks such as SQL injection or CSRF.

Project Material Details

Material at a Glance

  • Delivered via dashboard once confirmed
  • 51 Pages
  • 12,696 Words
  • 5 Complete Chapters
  • DOCX
  • National Diploma (ND)
  • Project topic and materials
  • 1300 Views
File Format
docx
Read Complete Project

Free gets you started. Membership gets you done.

One project topic is not enough. As a member, you can read unlimited materials, download according to your membership plan's allowance, request AI writing assistance for any new topic from Chapters 1–5, and access all our tools — from topic selection to complete project. Learn more.

Frequently Asked Questions

How do I download Project Materials for A DETECTION OF CROSS-SITE SCRIPTING ATTACK USING DYNAMIC ANALYSIS AND FUZZY INFERENCE SYSTEM?

Confirm if your membership plan is eligible and click on the download button to download the material and more.

Can I request custom Project Writing for this project topic?

Yes, our Custom Writing Service can prepare an original project based on your exact topic, school format, and requirements.

Chat with us on WhatsApp