UPM Institutional Repository

Machine and deep learning-based XSS detection approaches: a systematic literature review


Citation

Thajeel, Isam Kareem and Samsudin, Khairulmizam and Hashim, Shaiful Jahari and Hashim, Fazirulhisyam (2023) Machine and deep learning-based XSS detection approaches: a systematic literature review. Journal of King Saud University - Computer and Information Sciences, 35 (7). pp. 1-24. ISSN 1319-1578

Abstract

Web applications are paramount tools for facilitating services providing in the modern world. Unfortunately, the tremendous growth in the web application usage has resulted in a rise in cyberattacks. Cross-site scripting (XSS) is one of the most frequent cyber security attack vectors that threaten the end user as well as the service provider with the same degree of severity. Recently, an obvious increase of the Machine learning and deep learning ML/DL techniques adoption in XSS attack detection. The goal of this review is to come with a special attention and highlight of Machine learning and deep learning approaches. Thus, in this paper, we present a review of recent advances applied in ML/DL for XSS attack detection and classification. The existing proposed ML/DL approaches for XSS attack detection are analyzed and taxonomized comprehensively in terms of domain areas, data preprocessing, feature extraction, feature selection, dimensionality reduction, Data imbalance, performance metrics, datasets, and data types. Our analysis reveals that the way of how the XSS data is preprocessed considerably impacts the performance and the attack detection models. Proposing a full preprocessing cycle reveals how various ML/DL approaches for XSS attacks detection take advantage of different input data preprocessing techniques. The most used ML/DL and preprocessing stages have also been identified. The limitations of existing ML/DL-based XSS attack detection mechanisms are highlighted to identify the potential gaps and future trends.


Download File

[img] Text
1-s2.0-S1319157823001829-main.pdf - Published Version
Restricted to Repository staff only
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (1MB)

Additional Metadata

Item Type: Article
Divisions: Faculty of Engineering
DOI Number: https://doi.org/10.1016/j.jksuci.2023.101628
Publisher: Elsevier
Keywords: Cross-site scripting (XSS) attacks; Web application security; Cybersecurity; Machine learning; Deep learning
Depositing User: Ms. Nur Aina Ahmad Mustafa
Date Deposited: 06 Nov 2024 01:41
Last Modified: 06 Nov 2024 01:41
Altmetrics: http://www.altmetric.com/details.php?domain=psasir.upm.edu.my&doi=10.1016/j.jksuci.2023.101628
URI: http://psasir.upm.edu.my/id/eprint/109487
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item