Dissertation/ Thesis
Deep learning applied on Web security ; Apprentissage en profondeur appliqué à la sécurité du Web ; Deep learning applied on Web security: Statically Identifying Web vulnerabilities using Deep Learning ; Apprentissage en profondeur appliqué à la sécurité du Web: Identifié statiquement des vulnérabilités Web en utilisant des algorithmes d'apprentissage profond
| Τίτλος: | Deep learning applied on Web security ; Apprentissage en profondeur appliqué à la sécurité du Web ; Deep learning applied on Web security: Statically Identifying Web vulnerabilities using Deep Learning ; Apprentissage en profondeur appliqué à la sécurité du Web: Identifié statiquement des vulnérabilités Web en utilisant des algorithmes d'apprentissage profond |
|---|---|
| Συγγραφείς: | Maurel, Héloïse |
| Συνεισφορές: | Secure Diffuse Programming (INDES), Inria Sophia Antipolis - Méditerranée (CRISAM), Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria), Université Côte d'Azur (UCA), INRIA : Institut national de recherche en sciences et technologies du numérique, Université Cote d'Azur, Tamara Rezk |
| Πηγή: | https://hal.inria.fr/tel-03849284 ; Computer Science [cs]. INRIA : Institut national de recherche en sciences et technologies du numérique; Université Cote d'Azur, 2022. English. ⟨NNT : ⟩. |
| Στοιχεία εκδότη: | HAL CCSD |
| Έτος έκδοσης: | 2022 |
| Συλλογή: | Archive ouverte HAL (Hyper Article en Ligne, CCSD - Centre pour la Communication Scientifique Directe) |
| Θεματικοί όροι: | Web Application Security, Web Security, Web Applications, Server-side processing, Vulnerabilities detection, Deep learning DL, Artificial Inteligence AI, Machine Learning, Programming Language Processing PLP, Natural Language Processing NLP, Code Injection, XSS, Cross-Site Scripting, Databases and Data Security, Database benchmarks, Web language programming, Sécurité du Web, Apprentissage en profondeur, Faille de sécurité Web, Injection de code, Traitement automatique du langage naturel, Traitement automatique des langages de programmation, Base de données, Langage de programmation Web, Application Web, [INFO]Computer Science [cs], [INFO.INFO-AI]Computer Science [cs]/Artificial Intelligence [cs.AI], [INFO.INFO-CR]Computer Science [cs]/Cryptography and Security [cs.CR], [INFO.INFO-DB]Computer Science [cs]/Databases [cs.DB], [INFO.INFO-DS]Computer Science [cs]/Data Structures and Algorithms [cs.DS] |
| Περιγραφή: | Cross-site Scripting (XSS) is ranked number two in the top 25 of the Common Weaknesses Enumeration (2021) and places this vulnerability as one of the most dangerous among programming errors.XSS occurs when a web application improperly neutralises user-controllable input before it is placed in the output used on a web page that is served to other users. With this type of vulnerability, an attacker can perform malicious activities such as transferring private information from the victim's browser, sending malicious requests to a website on behalf of the victim, emulating trusted websites and inciting victims to enter private information, compromising the victim's website account, etc.In the first part of this manuscript, we investigate the detection of XSS vulnerabilities using deep learning algorithms.In particular, we compare two code representations based on natural language processing (NLP) and programming language processing (PLP) in two server-side languages, PHP and Node.js.We rebuild the PHP NIST generator, fix inconsistencies related to OWAPS rules to prevent XSS vulnerabilities, and extend the database. We build a new server-side code generator for Node.js. We also compare the PHP results obtained on two types of database distributions. The NLP representation has a better recall when HTML, JavaScript and CSS are included as code.We compare the results obtained by our deep learning models capable of detecting XSS vulnerabilities with three well-known static XSS vulnerability scanners for PHP code, ProgPilot, Pixy and RIPS and a well-known scanner for Nodejs, AppScan. The results of our analysers overcome the results of existing tools in all cases.We also compare XSS vulnerability detection in Node.js and a multi-tier JavaScript-based language called Hop.js using the PLP deep learning technique. In this sense, we build a new generator for Hop.js, and create a database for this language. With deep learning models trained to detect XSS on Hop.js, we obtain better recalls than Node.js models despite the lower ... |
| Τύπος εγγράφου: | doctoral or postdoctoral thesis |
| Γλώσσα: | English |
| Relation: | tel-03849284; https://hal.inria.fr/tel-03849284; https://hal.inria.fr/tel-03849284v2/document; https://hal.inria.fr/tel-03849284v2/file/MAUREL_Thesis.pdf |
| Διαθεσιμότητα: | https://hal.inria.fr/tel-03849284 https://hal.inria.fr/tel-03849284v2/document https://hal.inria.fr/tel-03849284v2/file/MAUREL_Thesis.pdf |
| Rights: | info:eu-repo/semantics/OpenAccess |
| Αριθμός Καταχώρησης: | edsbas.B98E1444 |
| Βάση Δεδομένων: | BASE |
καταχωρήστε σχόλιο πρώτοι!