Skip to content

About

Cross Site Scripting (XSS) Attack Detection using Machine Learning

Resources

Stars

0 stars

Watchers

1 watching

Forks

Repository files navigation

ML-XSS Detection

A Machine Learning-based system to detect Cross-Site Scripting (XSS) attacks in URLs using multiple classifiers including Decision Trees, SVM, Naive Bayes, KNN, Random Forest, and Neural Networks.

Overview

This project uses Doc2Vec and various machine learning models to classify URLs as either malicious (containing XSS) or normal. The system achieves this by:

  1. Converting URLs into feature vectors using Doc2Vec

  2. Extracting additional features based on common XSS patterns

  3. Using an ensemble of machine learning models for classification

Install Required Python Packages

Run the following command to install the required Python packages:

pip install numpy pickle nltk gensim urllib scikit-learn pandas sklearn

Data Format

Training Data

  • XSS_urls.txt: One URL per line containing XSS payloads
  • normal_urls.txt: One URL per line containing benign URLs

Test Data

  • test.txt: One URL per line to be classified

Usage

  1. Training the Models

    • Open and run IS_Project_Train.ipynb
    • This will:
      • Load XSS_urls.txt and normal_urls.txt from data/ directory
      • Process the training data
      • Create feature vectors
      • Train all models
      • Save models to the saved_models/ directory
  2. Testing/Prediction

    • Open and run IS_Project_Test.ipynb
    • This will:
      • Load the trained models
      • Process URLs from test.txt in data/ directory
      • Output classification results for each URL
      • Provide a summary of XSS vs Normal URLs detected

Model Weights

The final classification uses a weighted ensemble of models:

  • MLPClassifier: 30%
  • RandomForestClassifier: 25%
  • DecisionTreeClassifier: 17.5%
  • SVC: 15%
  • KNeighborsClassifier: 7.5%
  • GaussianNB: 5%

A threshold of 0.5 is used to determine the final classification.

Features

The system extracts the following features from URLs:

  1. Doc2Vec embeddings
  2. Count of HTML malicious tags
  3. Count of malicious methods/events keywords
  4. JavaScript-related patterns
  5. Special character frequencies
  6. URL length
  7. Script pattern frequencies
  8. HTTP occurrence count

Output

The system will classify each URL and display results with color coding:

  • Red: XSS detected
  • Green: Normal URL

A summary will be provided showing:

  • Total URLs classified
  • Number of XSS URLs detected
  • Number of Normal URLs detected

About

Cross Site Scripting (XSS) Attack Detection using Machine Learning

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages