Passer à la navigation principale Passer à la recherche Passer au contenu principal

Prevention of cross-site scripting attacks on current web applications

  • Universitat Oberta de Catalunya
  • University of São Paulo

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

Security is becoming one of the major concerns for web applications and other Internet based services, which are becoming pervasive in all kinds of business models and organizations. Web applications must therefore include, in addition to the expected value offered to their users, reliable mechanisms to ensure their security. In this paper, we focus on the specific problem of preventing cross-site scripting attacks against web applications. We present a study of this kind of attacks, and survey current approaches for their prevention. The advantages and limitations of each proposal are discussed, and an alternative solution is introduced. Our proposition is based on the use of X.509 certificates, and XACML for the expression of authorization policies. By using our solution, developers and/or administrators of a given web application can specifically express its security requirements from the server side, and require the proper enforcement of such requirements on a compliant client. This strategy is seamlessly integrated in generic web applications by relaying in the SSL and secure redirect calls.

langue originaleAnglais
titreOn the Move to Meaningful Internet Systems 2007
Sous-titreCoopIS, DOA, ODBASE, GADA, and IS - OTM Confederated International Conferences CoopIS, DOA, ODBASE, GADA, and IS 2007, Proceedings
EditeurSpringer Verlag
Pages1770-1784
Nombre de pages15
EditionPART 2
ISBN (imprimé)9783540768357
Les DOIs
étatPublié - 1 janv. 2007
Modification externeOui
EvénementOTM Confederated International Conferences CoopIS, DOA, ODBASE, GADA, and IS 2007 - Vilamoura, Portugal
Durée: 25 nov. 200730 nov. 2007

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
nombrePART 2
Volume4804 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférenceOTM Confederated International Conferences CoopIS, DOA, ODBASE, GADA, and IS 2007
Pays/TerritoirePortugal
La villeVilamoura
période25/11/0730/11/07

Empreinte digitale

Examiner les sujets de recherche de « Prevention of cross-site scripting attacks on current web applications ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation