Dnyaneshwar K. Patil

Work place: Department of Computer Engineering, VIIT, SPPU University, Pune, India

E-mail: dnyaneshwar11.patil@gmail.com

Website:

Research Interests: Information Security, Network Security, World Wide Web

Biography

Dnyaneshwar K. Patil: Post-graduate student for master degree for computer engineering in Vishwakarma Institute of Information Technology (VIIT, Pune of SPPU University, interested in web security.

Author Articles
Automated Client-side Sanitizer for Code Injection Attacks

By Dnyaneshwar K. Patil Kailas R. Patil

DOI: https://doi.org/10.5815/ijitcs.2016.04.10, Pub. Date: 8 Apr. 2016

Web applications are useful for various online services. These web applications are becoming ubiquitous in our daily lives. They are used for multiple purposes such as e-commerce, financial services, emails, healthcare services and many other captious services. But the presence of vulnerabilities in the web application may become a serious cause for the security of the web application. A web application may contain different types of vulnerabilities. Cross-site scripting is one of the type of code injection attacks. According to OWASP TOP 10 vulnerability report, Cross-site Scripting (XSS) is among top 5 vulnerabilities. So this research work aims to implement an effective solution for the prevention of cross- site scripting vulnerabilities. In this paper, we implemented a novel client-side XSS sanitizer that prevents web applications from XSS attacks. Our sanitizer is able to detect cross-site scripting vulnerabilities at the client-side. It strengthens web browser, because modern web browser do not provide any specific notification, alert or indication of security holes or vulnerabilities and their presence in the web application.

[...] Read more.
Other Articles