Cross-site scripting detection with two-channel feature fusion embedded in self-attention mechanism. Issue 124 (January 2023)
- Record Type:
- Journal Article
- Title:
- Cross-site scripting detection with two-channel feature fusion embedded in self-attention mechanism. Issue 124 (January 2023)
- Main Title:
- Cross-site scripting detection with two-channel feature fusion embedded in self-attention mechanism
- Authors:
- Hu, Tianle
Xu, Chonghai
Zhang, Shenwen
Tao, Shuangshuang
Li, Luqun - Abstract:
- Abstract: In the era of big data, stealing users' private data has become one of the main targets of network hackers. In recent years, cross-site scripting (XSS) attacks to obtain users' privacy data have been one of the main web attack methods of network hackers. Traditional antivirus software cannot identify such cross-site scripting attacks. To identify cross-site scripting attacks quickly and accurately, we proposed a cross-site scripting detection model (C-BLA) with two-channel multi-scale feature fusion embedded in a self-attention mechanism. The model first maps cross-site scripting payloads into spatial vectors by data preprocessing using Word2Vec. Then the two-channel network performs feature extraction on the data. Channel I: extract local features of cross-site scripting payloads at different scales by designing parallel one-dimensional convolutional layers with different convolutional kernel sizes; Channel II: extract semantic information of cross-site scripting payloads from two directions of positive and negative order using a bidirectional Long-Short Term Memory network, and then embed the self-attention mechanism to strengthen the semantic information features. Experiments show that the proposed model achieves a precision rate of 99.8 % and a recall rate of 99.1 % for cross-site scripting detection, which is a certain improvement in detection rate compared with a single deep learning model and traditional machine learning methods. The two-channel featureAbstract: In the era of big data, stealing users' private data has become one of the main targets of network hackers. In recent years, cross-site scripting (XSS) attacks to obtain users' privacy data have been one of the main web attack methods of network hackers. Traditional antivirus software cannot identify such cross-site scripting attacks. To identify cross-site scripting attacks quickly and accurately, we proposed a cross-site scripting detection model (C-BLA) with two-channel multi-scale feature fusion embedded in a self-attention mechanism. The model first maps cross-site scripting payloads into spatial vectors by data preprocessing using Word2Vec. Then the two-channel network performs feature extraction on the data. Channel I: extract local features of cross-site scripting payloads at different scales by designing parallel one-dimensional convolutional layers with different convolutional kernel sizes; Channel II: extract semantic information of cross-site scripting payloads from two directions of positive and negative order using a bidirectional Long-Short Term Memory network, and then embed the self-attention mechanism to strengthen the semantic information features. Experiments show that the proposed model achieves a precision rate of 99.8 % and a recall rate of 99.1 % for cross-site scripting detection, which is a certain improvement in detection rate compared with a single deep learning model and traditional machine learning methods. The two-channel feature fusion of this model better solves the cross-site scripting detection problem. … (more)
- Is Part Of:
- Computers & security. Issue 124(2023)
- Journal:
- Computers & security
- Issue:
- Issue 124(2023)
- Issue Display:
- Volume 124, Issue 124 (2023)
- Year:
- 2023
- Volume:
- 124
- Issue:
- 124
- Issue Sort Value:
- 2023-0124-0124-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-01
- Subjects:
- Cross-site scripting -- Word2Vec -- Feature fusion -- Bidirectional long-short term memory -- Self-attention mechanism
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2022.102990 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 24445.xml