Fighting Against XSS Attacks. A Usability Evaluation of OWASP ESAPI Output Encoding

dc.contributor.author Wijayarathna, Chamila
dc.contributor.author Gamagedara Arachchilage, Nalin
dc.date.accessioned 2019-01-03T00:59:11Z
dc.date.available 2019-01-03T00:59:11Z
dc.date.issued 2019-01-08
dc.description.abstract Cross Site Scripting (XSS) is one of the most critical vulnerabilities exist in web applications. XSS can be prevented by encoding untrusted data that are loaded into browser content of web applications. Security Application Programming Interfaces (APIs) such as OWASP ESAPI provide output encoding functionalities for programmers to use to protect their applications from XSS attacks. However, XSS still being ranked as one of the most critical vulnerabilities in web applications suggests that programmers are not effectively using those APIs to encode untrusted data. Therefore, we conducted an experimental study with 10 programmers where they attempted to fix XSS vulnerabilities of a web application using the output encoding functionality of OWASP ESAPI. Results revealed 3 types of mistakes that programmers made which resulted in them failing to fix the application by removing XSS vulnerabilities. We also identified 16 usability issues of OWASP ESAPI. We identified that some of these usability issues as the reason for mistakes that programmers made. Based on these results, we provided suggestions on how the usability of output encoding APIs should be improved to give a better experience to programmers.
dc.format.extent 10 pages
dc.identifier.doi 10.24251/HICSS.2019.877
dc.identifier.isbn 978-0-9981331-2-6
dc.identifier.uri http://hdl.handle.net/10125/60167
dc.language.iso eng
dc.relation.ispartof Proceedings of the 52nd Hawaii International Conference on System Sciences
dc.rights Attribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.uri https://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subject Cybersecurity and Software Assurance
dc.subject Software Technology
dc.subject Cross Site Scripting, OWASP ESAPI, Usability, Security APIs
dc.title Fighting Against XSS Attacks. A Usability Evaluation of OWASP ESAPI Output Encoding
dc.type Conference Paper
dc.type.dcmi Text
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
0727.pdf
Size:
258.5 KB
Format:
Adobe Portable Document Format
Description: