A cross-site scripting (XSS) attack is one of the major web threats and security issues in web applications. Black-box web scanners are widely used to detect XSS vulnerabilities, but their effectiveness is often limited by a rigid testing strategy. This paper designs a scheme, named Automated XSS Vulnerability Detection (AUTOXSS), which trains an intelligent agent based on the Advantage Actor-Critic (A2C) reinforcement learning (RL) algorithm. This agent can automatically generate XSS attack payloads and perform vulnerability detection on target applications. AUTOXSS proposes a novel attack vector combination strategy and incorporates Web Application Firewall (WAF) feedback mechanisms to optimize the capability of the A2C algorithm, thereby improving the efficiency of the generation of effective attack vectors. Experimental results demonstrate that AUTOXSS outperforms comparable scanning tools across four benchmark tests, successfully detecting 286 XSS vulnerabilities with zero false positives while maintaining the lowest request frequency. The proposed methodology effectively enhances the overall efficiency of XSS vulnerability detection.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Fully Automated XSS Vulnerability Detection by Reinforcement Learning

  • Yanan Zhang,
  • Tingting Qiao,
  • Maode Ma

摘要

A cross-site scripting (XSS) attack is one of the major web threats and security issues in web applications. Black-box web scanners are widely used to detect XSS vulnerabilities, but their effectiveness is often limited by a rigid testing strategy. This paper designs a scheme, named Automated XSS Vulnerability Detection (AUTOXSS), which trains an intelligent agent based on the Advantage Actor-Critic (A2C) reinforcement learning (RL) algorithm. This agent can automatically generate XSS attack payloads and perform vulnerability detection on target applications. AUTOXSS proposes a novel attack vector combination strategy and incorporates Web Application Firewall (WAF) feedback mechanisms to optimize the capability of the A2C algorithm, thereby improving the efficiency of the generation of effective attack vectors. Experimental results demonstrate that AUTOXSS outperforms comparable scanning tools across four benchmark tests, successfully detecting 286 XSS vulnerabilities with zero false positives while maintaining the lowest request frequency. The proposed methodology effectively enhances the overall efficiency of XSS vulnerability detection.