{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T11:56:35Z","timestamp":1742385395095},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2022,12,8]],"date-time":"2022-12-08T00:00:00Z","timestamp":1670457600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,12,8]],"date-time":"2022-12-08T00:00:00Z","timestamp":1670457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Soft Comput"],"published-print":{"date-parts":[[2023,4]]},"DOI":"10.1007\/s00500-022-07697-2","type":"journal-article","created":{"date-parts":[[2022,12,8]],"date-time":"2022-12-08T20:04:45Z","timestamp":1670529885000},"page":"4593-4608","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/http\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Adaptive cross-site scripting attack detection framework for smart devices security using intelligent filters and attack ontology"],"prefix":"10.1007","volume":"27","author":[{"given":"Pooja","family":"Chaudhary","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"B. B.","family":"Gupta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A. K.","family":"Singh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,12,8]]},"reference":[{"key":"7697_CR1","doi-asserted-by":"publisher","first-page":"92687","DOI":"10.1109\/ACCESS.2020.2992820","volume":"8","author":"AA Abd El-Latif","year":"2020","unstructured":"Abd El-Latif AA, Abd-El-Atty B, Venegas-Andraca SE, Elwahsh H, Piran MJ, Bashir AK et al (2020) Providing end-to-end security using quantum walks in IoT networks. IEEE Access 8:92687\u201392696","journal-title":"IEEE Access"},{"issue":"6","key":"7697_CR2","doi-asserted-by":"publisher","first-page":"4723","DOI":"10.1109\/JIOT.2020.3028742","volume":"8","author":"S Abdulrahman","year":"2021","unstructured":"Abdulrahman S, Tout H, Mourad A, Talhi C (2021) FedMCCS: multicriteria client selection model for optimal IoT federated learning. IEEE Internet Things J 8(6):4723\u20134735. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/JIOT.2020.3028742","journal-title":"IEEE Internet Things J"},{"key":"7697_CR3","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1016\/j.sysarc.2015.11.001","volume":"64","author":"MA Ahmed","year":"2016","unstructured":"Ahmed MA, Ali F (2016) Multiple-path testing for cross site scripting using genetic algorithms. J Syst Architect 64:50\u201362","journal-title":"J Syst Architect"},{"key":"7697_CR4","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3203249","author":"S Arisdakessian","year":"2022","unstructured":"Arisdakessian S, Wahab OA, Mourad A, Otrok H, Guizani M (2022) A survey on IoT intrusion detection: federated learning, game theory, social psychology and explainable AI as future directions. IEEE Internet Things J. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/JIOT.2022.3203249","journal-title":"IEEE Internet Things J"},{"key":"7697_CR5","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108040","volume":"192","author":"L Babun","year":"2021","unstructured":"Babun L, Denney K, Celik ZB, McDaniel P, Uluagac AS (2021) A survey on IoT platforms: Communication, security, and privacy perspectives. Comput Netw 192:108040","journal-title":"Comput Netw"},{"key":"7697_CR6","doi-asserted-by":"crossref","unstructured":"Banerjee R, Baksi A, Singh N, Bishnu SK (2020) Detection of XSS in web applications using Machine Learning Classifiers. In: 2020 4th international conference on electronics, materials engineering and nano-technology (IEMENTech). IEEE, pp 1\u20135","DOI":"10.1109\/IEMENTech51367.2020.9270052"},{"key":"7697_CR7","unstructured":"Richardson L (2007) Beautiful soup documentation. Dosegljivo. https:\/\/2.zoppoz.workers.dev:443\/https\/www.crummy.com\/software\/BeautifulSoup\/bs4\/doc\/. Accessed 7 Aug 2018"},{"key":"7697_CR8","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102710","volume":"118","author":"P Chaudhary","year":"2022","unstructured":"Chaudhary P, Gupta BB, Singh AK (2022) Securing heterogeneous embedded devices against XSS attack in intelligent IoT system. Comput Secur 118:102710","journal-title":"Comput Secur"},{"key":"7697_CR9","doi-asserted-by":"crossref","unstructured":"Chaudhary P, Gupta S, Gupta BB (2016) Auditing defense against XSS worms in online social network-based web applications. In: Handbook of research on modern cryptographic solutions for computer and cyber security. IGI Global, pp 216\u2013245","DOI":"10.4018\/978-1-5225-0105-3.ch010"},{"issue":"1","key":"7697_CR10","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1109\/TDSC.2020.2999866","volume":"19","author":"M Chehab","year":"2022","unstructured":"Chehab M, Mourad A (2022) LP-SBA-XACML: lightweight semantics based scheme enabling intelligent behavior-aware privacy for IoT. IEEE Trans Dependable Secure Comput 19(1):161\u2013175. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/TDSC.2020.2999866","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"1","key":"7697_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s12864-019-6413-7","volume":"21","author":"D Chicco","year":"2020","unstructured":"Chicco D, Jurman G (2020) The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation. BMC Genom 21(1):1\u201313","journal-title":"BMC Genom"},{"key":"7697_CR12","unstructured":"Kaggle (2019) Cross-site scripting dataset. https:\/\/2.zoppoz.workers.dev:443\/https\/www.kaggle.com\/syedsaqlainhussain\/cross-site-scripting-xss-dataset-for-deep-learning. Accessed 2 Jan 2022"},{"key":"7697_CR13","unstructured":"DOMPurify 2.3.0 (2021) https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/cure53\/DOMPurify. Accessed 2 Jan 2022"},{"key":"7697_CR14","doi-asserted-by":"crossref","unstructured":"Duchene F, Rawat S, Richier JL, Groz R (2014) KameleonFuzz: evolutionary fuzzing for black-box XSS detection. In: Proceedings of the 4th ACM conference on data and application security and privacy, pp 37\u201348","DOI":"10.1145\/2557547.2557550"},{"key":"7697_CR15","doi-asserted-by":"crossref","unstructured":"Fang Y, Li Y, Liu L, Huang C (2018). DeepXSS: cross site scripting detection based on deep learning. In Proceedings of the 2018 international conference on computing and artificial intelligence, pp 47\u201351","DOI":"10.1145\/3194452.3194469"},{"key":"7697_CR16","unstructured":"Github, XSS Payload Dataset (2021) https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/ismailtasdelen\/xss-payload-list. Accessed 2 Jan 2022"},{"issue":"2","key":"7697_CR17","first-page":"118","volume":"11","author":"BB Gupta","year":"2015","unstructured":"Gupta BB, Gupta S, Gangwar S, Kumar M, Meena PK (2015) Cross-site scripting (XSS) abuse and defense: exploitation on several testing bed environments and its defense. J Inf Priv Secur 11(2):118\u2013136","journal-title":"J Inf Priv Secur"},{"key":"7697_CR18","doi-asserted-by":"publisher","DOI":"10.1201\/9780429351327","volume-title":"Cross-site scripting attacks: classification, attack, and countermeasures","author":"BB Gupta","year":"2020","unstructured":"Gupta BB, Chaudhary P (2020) Cross-site scripting attacks: classification, attack, and countermeasures. CRC Press"},{"issue":"4","key":"7697_CR19","doi-asserted-by":"publisher","first-page":"85","DOI":"10.4018\/JOEUC.2020100105","volume":"32","author":"BB Gupta","year":"2020","unstructured":"Gupta BB, Chaudhary P, Gupta S (2020) Designing a XSS defensive framework for web servers deployed in the existing smart city infrastructure. J Organ End User Comput (JOEUC) 32(4):85\u2013111","journal-title":"J Organ End User Comput (JOEUC)"},{"issue":"3","key":"7697_CR20","first-page":"1","volume":"7","author":"S Gupta","year":"2017","unstructured":"Gupta S, Gupta BB (2017) Detection, avoidance, and attack pattern mechanisms in modern web application vulnerabilities: present and future challenges. Int J Cloud Appl Comput (IJCAC) 7(3):1\u201343","journal-title":"Int J Cloud Appl Comput (IJCAC)"},{"key":"7697_CR21","doi-asserted-by":"crossref","unstructured":"Gupta S, Gupta BB (2015) PHP-sensor: a prototype method to discover workflow violation and XSS vulnerabilities in PHP web applications. In: Proceedings of the 12th ACM international conference on computing frontiers, pp 1\u20138","DOI":"10.1145\/2742854.2745719"},{"issue":"3","key":"7697_CR22","doi-asserted-by":"publisher","first-page":"897","DOI":"10.1007\/s13369-015-1891-7","volume":"41","author":"S Gupta","year":"2016","unstructured":"Gupta S, Gupta BB (2016) XSS-SAFE: a server-side approach to detect and mitigate cross-site scripting (XSS) attacks in JavaScript code. Arab J Sci Eng 41(3):897\u2013920","journal-title":"Arab J Sci Eng"},{"issue":"2","key":"7697_CR23","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1006\/knac.1993.1008","volume":"5","author":"TR Gruber","year":"1993","unstructured":"Gruber TR (1993) A translation approach to portable ontology specifications. Knowl Acquis 5(2):199\u2013220","journal-title":"Knowl Acquis"},{"key":"7697_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2019.100129","volume":"14","author":"H HaddadPajouh","year":"2021","unstructured":"HaddadPajouh H, Dehghantanha A, Parizi RM, Aledhari M, Karimipour H (2021) A survey on internet of things security: Requirements, challenges, and solutions. Internet Things 14:100129","journal-title":"Internet Things"},{"key":"7697_CR25","unstructured":"Html5lib parser (2020). https:\/\/2.zoppoz.workers.dev:443\/https\/pypi.org\/project\/html5lib\/. Accessed 11 Jan 2022"},{"key":"7697_CR26","unstructured":"HtmlSanitizer (2020). https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/mganss\/HtmlSanitizer. Accessed 11 Jan 2022"},{"issue":"9","key":"7697_CR27","doi-asserted-by":"publisher","first-page":"1464","DOI":"10.1109\/5.58325","volume":"78","author":"T Kohonen","year":"1990","unstructured":"Kohonen T (1990) The self-organizing map. Proc IEEE 78(9):1464\u20131480","journal-title":"Proc IEEE"},{"key":"7697_CR28","doi-asserted-by":"crossref","unstructured":"Law KM, Ip AW, Gupta BB, Geng S (eds) (2021) Managing IoT and mobile technologies with innovation, trust, and sustainable computing. CRC Press","DOI":"10.1201\/9780367822750"},{"key":"7697_CR29","doi-asserted-by":"crossref","unstructured":"Lei L, Chen M, He C, Li D (2020) XSS detection technology based on LSTM-attention. In: 2020 5th international conference on control, robotics and cybernetics (CRC). IEEE, pp 175\u2013180","DOI":"10.1109\/CRC51253.2020.9253484"},{"key":"7697_CR30","unstructured":"Lionel Sujay Vailshery (2021) IoT connected devices worldwide 2030. https:\/\/2.zoppoz.workers.dev:443\/https\/www.statista.com\/statistics\/802690\/worldwide-connected-devices-by-access-technology\/. Accessed 21 Jan 2022"},{"key":"7697_CR31","volume":"58","author":"FMM Mokbal","year":"2021","unstructured":"Mokbal FMM, Dan W, Xiaoxi W, Wenbin Z, Lihua F (2021) XGBXSS: an extreme gradient boosting detection framework for cross-site scripting attacks based on hybrid feature selection approach and parameters optimization. J Inf Secur Appl 58:102813","journal-title":"J Inf Secur Appl"},{"key":"7697_CR32","doi-asserted-by":"publisher","unstructured":"Mrad A, Al-Hilo A, Sharafeddine S, Assi C (2022) NOMA-aided UAV data collection from time-constrained IoT devices. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/ICC45855.2022.9838643","DOI":"10.1109\/ICC45855.2022.9838643"},{"key":"7697_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/IJSWIS.295551","volume":"18","author":"NTU Nhi","year":"2022","unstructured":"Nhi NTU, Le TM, Van TT (2022) a model of semantic-based image retrieval using C-tree and neighbor graph. Int J Semant Web Inf Syst (IJSWIS) 18:1\u201323. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.4018\/IJSWIS.295551","journal-title":"Int J Semant Web Inf Syst (IJSWIS)"},{"key":"7697_CR34","unstructured":"OWASP Java HTML Sanitizer (2019). https:\/\/2.zoppoz.workers.dev:443\/https\/owasp.org\/www-project-java-html-sanitizer\/. Accessed 10 Jan 2022"},{"key":"7697_CR35","unstructured":"OWASP top 10 web application security risks (2021) https:\/\/2.zoppoz.workers.dev:443\/https\/owasp.org\/Top10\/. Accessed 22 Jan 2022"},{"key":"7697_CR36","unstructured":"Prot\u00e9g\u00e9 Tool (2019). https:\/\/2.zoppoz.workers.dev:443\/https\/protege.stanford.edu\/. Accessed 10 Jan 2022"},{"key":"7697_CR37","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2019.106960","volume":"166","author":"GE Rodr\u00edguez","year":"2020","unstructured":"Rodr\u00edguez GE, Torres JG, Flores P, Benavides DE (2020) Cross-site scripting (XSS) attacks and mitigation: a survey. Comput Netw 166:106960","journal-title":"Comput Netw"},{"key":"7697_CR38","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1016\/j.entcs.2014.01.024","volume":"302","author":"MIP Salas","year":"2014","unstructured":"Salas MIP, Martins E (2014) Security testing methodology for vulnerabilities detection of xss in web services and ws-security. Electron Notes Theor Comput Sci 302:133\u2013154","journal-title":"Electron Notes Theor Comput Sci"},{"issue":"7","key":"7697_CR39","doi-asserted-by":"publisher","first-page":"2493","DOI":"10.1109\/TMC.2020.3042925","volume":"21","author":"M Samir","year":"2022","unstructured":"Samir M, Assi C, Sharafeddine S, Ghrayeb A (2022) Online altitude control and scheduling policy for minimizing aoi in UAV-assisted IoT wireless networks. IEEE Trans Mob Comput 21(7):2493\u20132505. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/TMC.2020.3042925","journal-title":"IEEE Trans Mob Comput"},{"key":"7697_CR40","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/IJSWIS.2020100101","volume":"16","author":"B Sejdiu","year":"2020","unstructured":"Sejdiu B, Ismaili F, Ahmedi L (2020) Integration of semantics into sensor data for the IoT: a systematic literature review. Int J Semant Web Inf Syst (IJSWIS) 16:1\u201325. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.4018\/IJSWIS.2020100101","journal-title":"Int J Semant Web Inf Syst (IJSWIS)"},{"key":"7697_CR41","doi-asserted-by":"publisher","unstructured":"Singamaneni KK, Dhiman G, Juneja S, Muhammad G, AlQahtani SA, Zaki J (2022) A novel QKD approach to enhance IIOT privacy and computational knacks. Sensors. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.3390\/s22186741","DOI":"10.3390\/s22186741"},{"key":"7697_CR42","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/IJSWIS.297143","volume":"18","author":"A Singh","year":"2022","unstructured":"Singh A, Gupta BB (2022) Distributed denial-of-service (DDoS) attacks and defense mechanisms in various web-enabled computing platforms: issues, challenges, and future research directions. Int J Semant Web Inf Syst (IJSWIS) 18:1\u201343. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.4018\/IJSWIS.297143","journal-title":"Int J Semant Web Inf Syst (IJSWIS)"},{"issue":"2","key":"7697_CR43","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3426972","volume":"22","author":"CL Stergiou","year":"2021","unstructured":"Stergiou CL, Psannis KE et al (2021) InFeMo: flexible big data management through a federated cloud system. ACM Trans Internet Technol (TOIT) 22(2):1\u201322","journal-title":"ACM Trans Internet Technol (TOIT)"},{"issue":"3","key":"7697_CR44","doi-asserted-by":"publisher","first-page":"20","DOI":"10.4018\/IJSWIS.2020070102","volume":"16","author":"A Tewari","year":"2020","unstructured":"Tewari A et al (2020) Secure timestamp-based mutual authentication protocol for IoT devices using rfid tags. Int J Semant Web Inf Syst (IJSWIS) 16(3):20\u201334","journal-title":"Int J Semant Web Inf Syst (IJSWIS)"},{"key":"7697_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.114386","volume":"168","author":"I Tariq","year":"2021","unstructured":"Tariq I, Sindhu MA, Abbasi RA, Khattak AS, Maqbool O, Siddiqui GF (2021) Resolving cross-site scripting attacks through genetic algorithm and reinforcement learning. Expert Syst Appl 168:114386","journal-title":"Expert Syst Appl"},{"issue":"3","key":"7697_CR46","doi-asserted-by":"publisher","first-page":"410","DOI":"10.3390\/sym12030410","volume":"12","author":"TC Truong","year":"2020","unstructured":"Truong TC, Diep QB, Zelinka I (2020) Artificial intelligence in the cyber domain: offense and defense. Symmetry 12(3):410","journal-title":"Symmetry"},{"issue":"11","key":"7697_CR47","first-page":"1769","volume":"38","author":"D Wang","year":"2017","unstructured":"Wang D, Gu M, Zhao W (2017) Cross-site script vulnerability penetration testing technology. J Harbin Eng Univer 38(11):1769\u20131774","journal-title":"J Harbin Eng Univer"},{"key":"7697_CR48","doi-asserted-by":"publisher","first-page":"10989","DOI":"10.1109\/ACCESS.2020.2965184","volume":"8","author":"X Zhang","year":"2020","unstructured":"Zhang X, Zhou Y, Pei S, Zhuge J, Chen J (2020a) Adversarial examples detection for XSS attacks based on generative adversarial networks. IEEE Access 8:10989\u201310996","journal-title":"IEEE Access"},{"key":"7697_CR49","doi-asserted-by":"crossref","unstructured":"Zhang WZ, Elgendy IA, Hammad M, Iliyasu AM, Du X, Guizani M, Abd El-Latif AA (2020b) Secure and optimized load balancing for multi-tier IoT and edge-cloud computing systems. IEEE Internet Things J 8(10):8119\u20138132","DOI":"10.1109\/JIOT.2020.3042433"},{"key":"7697_CR50","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1016\/j.cose.2018.12.016","volume":"82","author":"Y Zhou","year":"2019","unstructured":"Zhou Y, Wang P (2019) An ensemble learning approach for XSS attack detection with domain knowledge and threat intelligence. Comput Secur 82:261\u2013269","journal-title":"Comput Secur"},{"key":"7697_CR51","doi-asserted-by":"crossref","unstructured":"Zhou Z, Gaurav A, Gupta BB, Lytras MD, Razzak I (2021) A fine-grained access control and security approach for intelligent vehicular transport in 6g communication system. IEEE Trans Intell Transp Syst","DOI":"10.1109\/TITS.2021.3106825"}],"container-title":["Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/link.springer.com\/content\/pdf\/10.1007\/s00500-022-07697-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/link.springer.com\/article\/10.1007\/s00500-022-07697-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/link.springer.com\/content\/pdf\/10.1007\/s00500-022-07697-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,29]],"date-time":"2023-03-29T10:33:26Z","timestamp":1680086006000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/link.springer.com\/10.1007\/s00500-022-07697-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,8]]},"references-count":51,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,4]]}},"alternative-id":["7697"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/s00500-022-07697-2","relation":{},"ISSN":["1432-7643","1433-7479"],"issn-type":[{"value":"1432-7643","type":"print"},{"value":"1433-7479","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,8]]},"assertion":[{"value":"22 November 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 December 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have not disclosed any competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}