Prevention of Cross-Site Scripting Attacks on Current Web Applications

dc.contributor
Universitat Oberta de Catalunya. K-ryptography and Information Security for Open Networks (KISON)
dc.contributor.author
García Alfaro, Joaquín
dc.contributor.author
Navarro Arribas, Guillermo
dc.date
2010-02-16T11:56:43Z
dc.date
2010-02-16T11:56:43Z
dc.date
2007
dc.identifier.citation
GARCIA-ALFARO, J.; NAVARRO, G. (2007). "Prevention of Cross-Site Scripting Attacks on Current Web Applications". Lecture Notes in Computer Science. 4804, p. 1.770-1.784. ISSN: 0302-9743.
dc.identifier.citation
0302-9743
dc.identifier.citation
10.1007/978-3-540-76843-2_45
dc.identifier.uri
http://hdl.handle.net/10609/1320
dc.description.abstract
Security is becoming one of the major concerns for web applications and other Internet based services, which are becoming pervasive in all kinds of business models and organizations. Web applications must therefore include, in addition to the expected value offered to their users, reliable mechanisms to ensure their security. In this paper, we focus on the specific problem of preventing cross-site scripting attacks against web applications. We present a study of this kind of attacks, and survey current approaches for their prevention. The advantages and limitations of each proposal are discussed, and an alternative solution is introduced. Our proposition is based on the use of X.509 certificates, and XACML for the expression of authorization policies. By using our solution, developers and/or administrators of a given web application can specifically express its security requirements from the server side, and require the proper enforcement of such requirements on a compliant client. This strategy is seamlessly integrated in generic web applications by relaying in the SSL and secure redirect calls.
dc.language.iso
eng
dc.rights
The original publication is available at <a href="http://www.springerlink.com/content/e9057385714r6171">http://www.springerlink.com/content/e9057385714r6171</a>
dc.subject
Internet -- Security measures
dc.subject
Computer networks -- Security measures
dc.subject
Computer security
dc.subject
Internet -- Mesures de seguretat
dc.subject
Ordinadors, Xarxes d' -- Mesures de seguretat
dc.subject
Informàtica -- Mesures de seguretat
dc.subject
Internet -- Medidas de seguridad
dc.subject
Ordenadores, Redes de -- Medidas de seguridad
dc.subject
Informática -- Medidas de seguridad
dc.title
Prevention of Cross-Site Scripting Attacks on Current Web Applications
dc.type
info:eu-repo/semantics/article


Ficheros en el ítem

FicherosTamañoFormatoVer

No hay ficheros asociados a este ítem.

Este ítem aparece en la(s) siguiente(s) colección(ones)

Articles [361]