Your browser does not allow JavaScript!
JavaScript is necessary for the proper functioning of this website. Please enable JavaScript or use a modern browser.
|
|
SLO
|
ENG
|
Cookies and privacy
DKUM
EPF - Faculty of Business and Economics
FE - Faculty of Energy Technology
FERI - Faculty of Electrical Engineering and Computer Science
FF - Faculty of Arts
FGPA - Faculty of Civil Engineering, Transportation Engineering and Architecture
FKBV - Faculty of Agriculture and Life Sciences
FKKT - Faculty of Chemistry and Chemical Engineering
FL - Faculty of Logistic
FNM - Faculty of Natural Sciences and Mathematics
FOV - Faculty of Organizational Sciences in Kranj
FS - Faculty of Mechanical Engineering
FT - Faculty of Tourism
FVV - Faculty of Criminal Justice and Security
FZV - Faculty of Health Sciences
MF - Faculty of Medicine
PEF - Faculty of Education
PF - Faculty of Law
UKM - University of Maribor Library
UM - University of Maribor
UZUM - University of Maribor Press
COBISS
Faculty of Business and Economic, Maribor
Faculty of Agriculture and Life Sciences, Maribor
Faculty of Logistics, Celje, Krško
Faculty of Organizational Sciences, Kranj
Faculty of Criminal Justice and Security, Ljubljana
Faculty of Health Sciences
Library of Technical Faculties, Maribor
Faculty of Medicine, Maribor
Miklošič Library FPNM, Maribor
Faculty of Law, Maribor
University of Maribor Library
Bigger font
|
Smaller font
Introduction
Search
Browsing
Upload document
Statistics
Login
First page
>
Show document
Show document
Title:
Iskanje ranljivosti XSS v spletnih aplikacijah z uporabo metod strojnega učenja : magistrsko delo
Authors:
ID
Kozulić, Ivan
(
Author
)
ID
Lukač, Niko
(
Mentor
)
More about this mentor...
Files:
MAG_Kozulic_Ivan_2020.pdf
(1,24 MB)
MD5: 71526EE12E0241A652EE9084B5A344B8
PID:
20.500.12556/dkum/ca477e1b-5df1-4dd0-946c-fd324ca6a5b7
Language:
Slovenian
Work type:
Master's thesis/paper
Typology:
2.09 - Master's Thesis
Organization:
FERI - Faculty of Electrical Engineering and Computer Science
Abstract:
Cross-site scripting (XSS) napadi še vedno predstavljajo veliko varnostno tveganje pri spletnih aplikacijah. V magistrskem delu predstavljamo metodo za iskanje ranljivosti v JavaScript programski kodi, pri čemer smo uporabili algoritme strojnega učenja. V teoretičnem delu najprej opišemo osnovne koncepte napadov XSS in z njimi povezane ranljivosti. Predstavimo tudi sorodne pristope za iskanje ranljivosti XSS. V praktičnem delu magistrskega dela pa se posvetimo načinu izračuna značilnic iz JavaScript kode ter pripravi učne in testne množice. Na podlagi značilnic smo usposobili model strojnega učenja za ločevanje ranljivih od neranljivih aplikacij. Iz rezultatov sklepamo, da je metoda učinkovita in nudi dodatno podporo pri odkrivanju ranljivosti XSS.
Keywords:
varnost spletnih aplikacij
,
XSS
,
JavaScript
,
strojno učenje
Place of publishing:
Maribor
Place of performance:
Maribor
Publisher:
[I. Kozulić]
Year of publishing:
2020
Number of pages:
IX, 60 f.
PID:
20.500.12556/DKUM-76839
UDC:
004.774.056+004.85(043.2)
COBISS.SI-ID:
37733123
NUK URN:
URN:SI:UM:DK:16MHOYPH
Publication date in DKUM:
04.11.2020
Views:
1231
Downloads:
111
Metadata:
Categories:
KTFMB - FERI
Cite this work
Plain text
BibTeX
EndNote XML
EndNote/Refer
RIS
ABNT
ACM Ref
AMA
APA
Chicago 17th Author-Date
Harvard
IEEE
ISO 690
MLA
Vancouver
:
Copy citation
Average score:
(0 votes)
Your score:
Voting is allowed only for
logged in
users.
Share:
Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.
Licences
License:
CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:
http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:
The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:
14.07.2020
Secondary language
Language:
English
Title:
Xss vulnerabilities search in web applications by using machine learning approaches
Abstract:
Cross-site scripting (XSS) attacks are still a major threat to the security of web applications. In the master's thesis, we present a method for searching vulnerabilities in JavaScript code using machine learning algorithms. In the theoretical part, we first describe the basic concepts of XSS attacks and related vulnerabilities. We also present related approaches for finding XSS vulnerabilities. In the practical part of the thesis, we focus on the method for calculating the characteristics from the JavaScript code and the preparation of the train and test data set. Based on the characteristics, we trained the machine learning model to separate vulnerable from non-vulnerable applications. From the results, we conclude that the method is effective and offers additional support in detecting vulnerabilities.
Keywords:
web application security
,
XSS
,
JavaScript
,
machine learning
Comments
Leave comment
You must
log in
to leave a comment.
Comments (0)
0 - 0 / 0
There are no comments!
Back