跨站脚本攻击的防御方法、装置、电子设备、介质
By combining server-side and client-side defense mechanisms, utilizing keyword recognition models and user behavior analysis, and dynamically adjusting verification rules, the problem of insufficient XSS defense capabilities in existing technologies is solved, achieving more efficient and accurate cross-site scripting attack defense, and ensuring user security and system performance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2024-12-25
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies struggle to defend against new attack variants and dynamic attack patterns when defending against cross-site scripting (XSS) attacks. They lack dynamic behavior analysis, resulting in insufficient system security and accuracy. Furthermore, full interception increases computational resource consumption.
By receiving user input data on the server side, the system dynamically adjusts the verification rules using keyword recognition models and user behavior analysis. It combines data vectorization, word segmentation, and Long Short-Term Memory (LSTM) network models to identify and filter potential attacks, implement data desensitization and encrypted storage, and verify resource loading rules on the client side.
It improves the adaptability of the defense system, reduces false positives and false blocking, increases the utilization of computing resources, protects user information security, and enhances the access experience.
Smart Images

Figure CN119728262B_ABST