Your conditions: 黄娜娜
  • 一种基于支持向量机的跨站脚本漏洞检测技术

    Subjects: Computer Science >> Integration Theory of Computer Science submitted time 2018-05-20 Cooperative journals: 《计算机应用研究》

    Abstract: Cross-site scripting is a common way of exploiting Web application security vulnerabilities. A malicious user exploits a vulnerability to inject a malicious script into a web page, and when the user browses the page, it triggers the script, causing the attack to occur. This paper studied a recursive feature elimination algorithm based on regular expression and support vector machine (RE-SVM-RFE) for each kind of deformation. Firstly, the regular expression matching algorithm, to select a representative training set of characteristics, i. e. , the data preprocessing; reuse RE-SVM-RFE feature selection algorithm to select the optimal characteristics, and then the keyword feature offensive sort. Finally, it summarized the frequency of occurrence of the keyword feature, found that the higher the frequency the greater the likelihood loopholes. Experimental results show that, after the data RE-SVM-RFE recursive feature elimination after SVM feature selection algorithm, higher accuracy of prediction, and better sensitivity and specificity, the algorithm can effectively detect XSS.