WebSite Logo
  • Content
  • Similar Resources
  • Metadata
  • Cite This
  • Log-in
  • Fullscreen
Log-in
Do not have an account? Register Now
Forgot your password? Account recovery
  1. Science in China Series : Information Sciences
  2. Science in China Series : Information Sciences : Volume 58
  3. Science in China Series : Information Sciences : Volume 58, Issue 1, January 2015
  4. XAS: Cross-API scripting attacks in social ecosystems
Loading...

Please wait, while we are loading the content...

Science in China Series : Information Sciences : Volume 61
Science in China Series : Information Sciences : Volume 60
Science in China Series : Information Sciences : Volume 59
Science in China Series : Information Sciences : Volume 58
Science in China Series : Information Sciences : Volume 58, Issue 12, December 2015
Science in China Series : Information Sciences : Volume 58, Issue 11, November 2015
Science in China Series : Information Sciences : Volume 58, Issue 10, October 2015
Science in China Series : Information Sciences : Volume 58, Issue 9, September 2015
Science in China Series : Information Sciences : Volume 58, Issue 8, August 2015
Science in China Series : Information Sciences : Volume 58, Issue 7, July 2015
Science in China Series : Information Sciences : Volume 58, Issue 6, June 2015
Science in China Series : Information Sciences : Volume 58, Issue 5, May 2015
Science in China Series : Information Sciences : Volume 58, Issue 4, April 2015
Science in China Series : Information Sciences : Volume 58, Issue 3, March 2015
Science in China Series : Information Sciences : Volume 58, Issue 2, February 2015
Science in China Series : Information Sciences : Volume 58, Issue 1, January 2015
Rational construction of a cellular memory inverter
QoE-driven resource allocation for mobile IP services in wireless network
A fractal and scale-free model of complex networks with hub attraction behaviors
Decidable subsets of open logic and an algorithm for R-calculus
Static output feedback stabilization for systems with time-varying delay based on a matrix transformation method
QSobel: A novel quantum image edge extraction algorithm
On τ-time secure key agreement
Strategies for network security
XAS: Cross-API scripting attacks in social ecosystems
Cryptography on twisted Edwards curves over local fields
Improving multiprocessor performance with fine-grain coherence bypass
Collusion-resistant convertible ring signature schemes
Single image haze removal via depth-based contrast stretching transform
Characteristic model-based H $_{2}$/H $_{∞}$ robust adaptive control during the re-entry of hypersonic cruise vehicles
Link prediction in social networks: the state-of-the-art
Science in China Series : Information Sciences : Volume 57
Science in China Series : Information Sciences : Volume 56
Science in China Series : Information Sciences : Volume 55
Science in China Series : Information Sciences : Volume 54
Science in China Series : Information Sciences : Volume 53
Science in China Series : Information Sciences : Volume 52
Science in China Series : Information Sciences : Volume 51
Science in China Series : Information Sciences : Volume 50
Science in China Series : Information Sciences : Volume 49
Science in China Series : Information Sciences : Volume 48
Science in China Series : Information Sciences : Volume 47
Science in China Series : Information Sciences : Volume 46
Science in China Series : Information Sciences : Volume 45
Science in China Series : Information Sciences : Volume 44

Similar Documents

...
Cross-Site Scripting Attacks in Social Network APIs

Article

...
Defending against Cross-Site Scripting Attacks

Article

...
Cross-Site Scripting Attacks in Social Network APIs

Article

...
Cross-Site Scripting Attacks

Chapter

...
Security Vulnerabilities in the Same-Origin Policy: Implications and Alternatives

Article

...
Prevention Of Cross-Site Scripting Attacks XSS On Web Applications In The Client Side

Article

...
XSSDS: Server-Side Detection of Cross-Site Scripting Attacks

Article

...
Protection of Web Applications from Cross-Site Scripting Attacks in Browser Side

Article

...
A solution to block Cross Site Scripting Vulnerabilities based on Service Oriented Architecture

Article

XAS: Cross-API scripting attacks in social ecosystems

Content Provider Springer Nature Link
Author Zhang, YuQing Liu, QiXu Luo, QiHan Wang, XiaLi
Copyright Year 2014
Abstract With the rapid development of online social networks, various Web application programming interfaces (APIs) on social platforms are released to share profitable social data with all kinds of third-party online services. However, it also brings new risks to social networks once Web APIs are insecurely designed, implemented, and invoked. The focused topic in this paper is security analysis of a new type of cross-site scripting (XSS) which is based on Web APIs in new complicated social ecosystems which consist of social networks, third-party apps, and other online services. In this paper, we refer to Web API-based XSS as cross-API scripting (XAS). For the first time, we take typical XAS attacks in diversified context as cases to demonstrate the new exploiting opportunities and threats in social ecosystems. Also, we design a tool to identify the design and implementation flaws of Web APIs in 11 popular social networks. We discover several security flaws of API via our experiment. According to the results, we conclude causes of XAS flaws in depth. We also examined 143 Web-based apps and verified the prevalence of XAS flaws. Finally, we proposed preliminary measures both in social networks and third-party applications to alleviate XAS.
Starting Page 1
Ending Page 14
Page Count 14
File Format PDF
ISSN 1674733X
Journal Science in China Series : Information Sciences
Volume Number 58
Issue Number 1
e-ISSN 18691919
Language English
Publisher Science China Press
Publisher Date 2014-09-29
Publisher Place Heidelberg
Access Restriction One Nation One Subscription (ONOS)
Subject Keyword Web security social network Web APIs cross-API scripting cross-site scripting Information Systems and Communication Service
Content Type Text
Resource Type Article
Subject Computer Science
  • About
  • Disclaimer
  • Feedback
  • Sponsor
  • Contact
  • Chat with Us
About National Digital Library of India (NDLI)
NDLI logo

National Digital Library of India (NDLI) is a virtual repository of learning resources which is not just a repository with search/browse facilities but provides a host of services for the learner community. It is sponsored and mentored by Ministry of Education, Government of India, through its National Mission on Education through Information and Communication Technology (NMEICT). Filtered and federated searching is employed to facilitate focused searching so that learners can find the right resource with least effort and in minimum time. NDLI provides user group-specific services such as Examination Preparatory for School and College students and job aspirants. Services for Researchers and general learners are also provided. NDLI is designed to hold content of any language and provides interface support for 10 most widely used Indian languages. It is built to provide support for all academic levels including researchers and life-long learners, all disciplines, all popular forms of access devices and differently-abled learners. It is designed to enable people to learn and prepare from best practices from all over the world and to facilitate researchers to perform inter-linked exploration from multiple sources. It is developed, operated and maintained from Indian Institute of Technology Kharagpur.

Learn more about this project from here.

Disclaimer

NDLI is a conglomeration of freely available or institutionally contributed or donated or publisher managed contents. Almost all these contents are hosted and accessed from respective sources. The responsibility for authenticity, relevance, completeness, accuracy, reliability and suitability of these contents rests with the respective organization and NDLI has no responsibility or liability for these. Every effort is made to keep the NDLI portal up and running smoothly unless there are some unavoidable technical issues.

Feedback

Sponsor

Ministry of Education, through its National Mission on Education through Information and Communication Technology (NMEICT), has sponsored and funded the National Digital Library of India (NDLI) project.

Contact National Digital Library of India
Central Library (ISO-9001:2015 Certified)
Indian Institute of Technology Kharagpur
Kharagpur, West Bengal, India | PIN - 721302
See location in the Map
03222 282435
Mail: support@ndl.gov.in
Sl. Authority Responsibilities Communication Details
1 Ministry of Education (GoI),
Department of Higher Education
Sanctioning Authority https://www.education.gov.in/ict-initiatives
2 Indian Institute of Technology Kharagpur Host Institute of the Project: The host institute of the project is responsible for providing infrastructure support and hosting the project https://www.iitkgp.ac.in
3 National Digital Library of India Office, Indian Institute of Technology Kharagpur The administrative and infrastructural headquarters of the project Dr. B. Sutradhar  bsutra@ndl.gov.in
4 Project PI / Joint PI Principal Investigator and Joint Principal Investigators of the project Dr. B. Sutradhar  bsutra@ndl.gov.in
Prof. Saswat Chakrabarti  will be added soon
5 Website/Portal (Helpdesk) Queries regarding NDLI and its services support@ndl.gov.in
6 Contents and Copyright Issues Queries related to content curation and copyright issues content@ndl.gov.in
7 National Digital Library of India Club (NDLI Club) Queries related to NDLI Club formation, support, user awareness program, seminar/symposium, collaboration, social media, promotion, and outreach clubsupport@ndl.gov.in
8 Digital Preservation Centre (DPC) Assistance with digitizing and archiving copyright-free printed books dpc@ndl.gov.in
9 IDR Setup or Support Queries related to establishment and support of Institutional Digital Repository (IDR) and IDR workshops idr@ndl.gov.in
I will try my best to help you...
Cite this Content
Loading...