Auditing Defense Against XSS Worms in Online Social Network-Based Web Applications

Author(s):  
Pooja Chaudhary ◽  
Shashank Gupta ◽  
B. B. Gupta

Nowadays, users of Online Social Network (OSN) are less familiar with cyber security threats that occur in such networks, comprising Cross-Site Scripting (XSS) worms, Distributed Denial of Service (DDoS) attacks, Phishing, etc. Numerous defensive methodologies exist for mitigating the effect of DDoS attacks and Phishing vulnerabilities from OSN. However, till now, no such robust defensive solution is proposed for the complete alleviation of XSS worms from such networks. This chapter discusses the detailed incidences of XSS attacks in the recent period on the platforms of OSN. A high level of taxonomy of XSS worms is illustrated in this article for the precise interpretation of its exploitation in multiple applications of OSN like Facebook, Twitter, LinkedIn, etc. We have also discussed the key contributions of current defensive solutions of XSS attacks on the existing platforms of OSN. Based on this study, we identified the current performance issues in these existing solutions and recommend future research guidelines.

Author(s):  
Pooja Chaudhary ◽  
Shashank Gupta ◽  
B. B. Gupta

Nowadays, users of Online Social Network (OSN) are less familiar with cyber security threats that occur in such networks, comprising Cross-Site Scripting (XSS) worms, Distributed Denial of Service (DDoS) attacks, Phishing, etc. Numerous defensive methodologies exist for mitigating the effect of DDoS attacks and Phishing vulnerabilities from OSN. However, till now, no such robust defensive solution is proposed for the complete alleviation of XSS worms from such networks. This chapter discusses the detailed incidences of XSS attacks in the recent period on the platforms of OSN. A high level of taxonomy of XSS worms is illustrated in this article for the precise interpretation of its exploitation in multiple applications of OSN like Facebook, Twitter, LinkedIn, etc. We have also discussed the key contributions of current defensive solutions of XSS attacks on the existing platforms of OSN. Based on this study, we identified the current performance issues in these existing solutions and recommend future research guidelines.


Author(s):  
Rochak Swami ◽  
Mayank Dave ◽  
Virender Ranga ◽  
Nikhil Tripathi ◽  
Abhijith Kalayil Shaji ◽  
...  

Distributed denial of service (DDoS) attacks have been a matter of serious concern for network administrators in the last two decades. These attacks target the resources such as memory, CPU cycles, and network bandwidth in order to make them unavailable for the benign users, thereby violating availability, one of the components of cyber security. With the existence of DDoS-as-a-service on internet, DDoS attacks have now become more lucrative for the adversaries to target a potential victim. In this work, the authors focus on countering DDoS attacks using one of the latest technologies called blockchain. In inception phase, utilizing blockchain for countering DDoS attacks has proved to be quite promising. The authors also compare existing blockchain-based defense mechanisms to counter DDoS attacks and analyze them. Towards the end of the work, they also discuss possible future research directions in this domain.


Author(s):  
Amit Sharma

Distributed Denial of Service attacks are significant dangers these days over web applications and web administrations. These assaults pushing ahead towards application layer to procure furthermore, squander most extreme CPU cycles. By asking for assets from web benefits in gigantic sum utilizing quick fire of solicitations, assailant robotized programs use all the capacity of handling of single server application or circulated environment application. The periods of the plan execution is client conduct checking and identification. In to beginning with stage by social affair the data of client conduct and computing individual user’s trust score will happen and Entropy of a similar client will be ascertained. HTTP Unbearable Load King (HULK) attacks are also evaluated. In light of first stage, in recognition stage, variety in entropy will be watched and malevolent clients will be recognized. Rate limiter is additionally acquainted with stop or downsize serving the noxious clients. This paper introduces the FAÇADE layer for discovery also, hindering the unapproved client from assaulting the framework.


Author(s):  
Eun-Joo Kim ◽  
Ji-Young Lim ◽  
Geun-Myun Kim ◽  
Seong-Kwang Kim

Improving nursing students’ subjective happiness is germane for efficiency in the nursing profession. This study examined the subjective happiness of nursing students by applying social network analysis (SNA) and developing a strategy to improve the subjective happiness of nursing. The study adopted a cross sectional survey to measure subjective happiness and social network of 222 nursing students. The results revealed that the centralization index, which is a measure of intragroup interactions from the perspective of an entire network, was higher in the senior year compared with the junior year. Additionally, the indegree, outdegree, and centrality of the social network of students with a high level of subjective happiness were all found to be high. This result suggests that subjective happiness is not just an individual’s psychological perception, but can also be expressed more deeply depending on the subject’s social relationships. Based on the study’s results, to strengthen self-efficacy and resilience, it is necessary to utilize strategies that activate group dynamics, such as team activities, to improve subjective happiness. The findings can serve as basic data for future research focused on improving nursing students’ subjective happiness by consolidating team-learning social networks through a standardized program approach within a curriculum or extracurricular programs.


Author(s):  
Mohana Shanmugam ◽  
Yusmadi Yah Jusoh ◽  
Rozi Nor Haizan Nor ◽  
Marzanah A. Jabar

The social network surge has become a mainstream subject of academic study in a myriad of disciplines. This chapter posits the social network literature by highlighting the terminologies of social networks and details the types of tools and methodologies used in prior studies. The list is supplemented by identifying the research gaps for future research of interest to both academics and practitioners. Additionally, the case of Facebook is used to study the elements of a social network analysis. This chapter also highlights past validated models with regards to social networks which are deemed significant for online social network studies. Furthermore, this chapter seeks to enlighten our knowledge on social network analysis and tap into the social network capabilities.


Author(s):  
Khalid Al-Begain ◽  
Michal Zak ◽  
Wael Alosaimi ◽  
Charles Turyagyenda

The chapter presents current security concerns in the Cloud Computing Environment. The cloud concept and operation raise many concerns for cloud users since they have no control of the arrangements made to protect the services and resources offered. Additionally, it is obvious that many of the cloud service providers will be subject to significant security attacks. Some traditional security attacks such as the Denial of Service attacks (DoS) and distributed DDoS attacks are well known, and there are several proposed solutions to mitigate their impact. However, in the cloud environment, DDoS becomes more severe and can be coupled with Economical Denial of Sustainability (EDoS) attacks. The chapter presents a general overview of cloud security, the types of vulnerabilities, and potential attacks. The chapter further presents a more detailed analysis of DDoS attacks' launch mechanisms and well-known DDoS defence mechanisms. Finally, the chapter presents a DDoS-Mitigation system and potential future research directions.


2018 ◽  
pp. 1511-1554
Author(s):  
Khalid Al-Begain ◽  
Michal Zak ◽  
Wael Alosaimi ◽  
Charles Turyagyenda

The chapter presents current security concerns in the Cloud Computing Environment. The cloud concept and operation raise many concerns for cloud users since they have no control of the arrangements made to protect the services and resources offered. Additionally, it is obvious that many of the cloud service providers will be subject to significant security attacks. Some traditional security attacks such as the Denial of Service attacks (DoS) and distributed DDoS attacks are well known, and there are several proposed solutions to mitigate their impact. However, in the cloud environment, DDoS becomes more severe and can be coupled with Economical Denial of Sustainability (EDoS) attacks. The chapter presents a general overview of cloud security, the types of vulnerabilities, and potential attacks. The chapter further presents a more detailed analysis of DDoS attacks' launch mechanisms and well-known DDoS defence mechanisms. Finally, the chapter presents a DDoS-Mitigation system and potential future research directions.


Author(s):  
Jianping Peng ◽  
Jing ("Jim") Quan ◽  
Guoying Zhang ◽  
Alan J. Dubinsky

This chapter combines three less-studied factors on employee knowledge sharing, namely, social relationship, contextual performance, and IT competence. Using a survey study that was targeted to professional employees in a R&D department, we reveal that both social relationship—which incorporates degree of centrality of employee's social network and frequency of interpersonal interaction—and employee's contextual performance have significant positive impacts on knowledge sharing. This association, however, is found to be further positively moderated by employee's IT competence. Our work extends the literature pertaining to knowledge sharing by, not only providing an enhanced approach to measure social relationship, but also emphasizing that social relationship or contextual performance can magnify the impact on knowledge sharing through a high level of IT competence. The findings provide managerial and future research insights pertaining to promoting knowledge sharing by enhancing social relationship, rewarding contextual performance, and improving IT competence of employees.


Electronics ◽  
2020 ◽  
Vol 9 (11) ◽  
pp. 1827
Author(s):  
Waleed Nazih ◽  
Wail S. Elkilani ◽  
Habib Dhahri ◽  
Tamer Abdelkader

Voice over IP (VoIP) services hold promise because of their offered features and low cost. Most VoIP networks depend on the Session Initiation Protocol (SIP) to handle signaling functions. The SIP is a text-based protocol that is vulnerable to many attacks. Denial of Service (DoS) and distributed denial of service (DDoS) attacks are the most harmful types of attacks, because they drain VoIP resources and render SIP service unavailable to legitimate users. In this paper, we present recently introduced approaches to detect DoS and DDoS attacks, and classify them based on various factors. We then analyze these approaches according to various characteristics; furthermore, we investigate the main strengths and weaknesses of these approaches. Finally, we provide some remarks for enhancing the surveyed approaches and highlight directions for future research to build effective detection solutions.


Author(s):  
Hosam F. El-Sofany ◽  
Samir Abou El-Seoud

Cloud computing is a new paradigm for hosting hardware and software resources and provides a web-based services to organizations and consumers. It also provides an easy to use and on-demand access to cloud based computing resources that can be published by easy, minimal administration and with a great efficiency. Services of cloud computing are accessing and sharing through internet connection thus it is open for attacker to attack on its security. Application layer based attacks is one of Distributed Denial of Service attacks (DDoS) that can cause a big problem in cloud security. The main objective of DDoS attacks is to infect computer resources (e.g., software applications, network, CPU, etc.) and make them not working properly for the authorized users. In DDoS, the attacker tries to overload the web-based service with traffic. HTTP and XML-based DDoS attacks are founded under the application layer based category of DoS attacks. This category of attack is focused on particular web applications. The main objective of this research paper is to introduce an effective approach to protect cloud-based systems against application layer based attacks. Complexity analysis, effectiveness and performance evaluations of the presented approach are presented.  The feedbacks of the experimental results were highly promising, for protecting cloud computing systems against both DoS and DDoS attacks. Correlation analysis model is also used to validate the efficiency of the proposed approach.


Sign in / Sign up

Export Citation Format

Share Document