Cross-site scripting (XSS) attacks are a critical threat to Web applications. These attacks allow the injection of malicious scripts into trusted websites, which can lead to data theft, session hijacking, and the compromise of user accounts. In this paper, we propose a novel forensic analysis tool specifically designed for mobile devices, which enables investigators to efficiently analyze Web server access logs, which are critical forensic resources, to detect potential traces of XSS attacks. The mobile-first design ensures that essential forensic data can be quickly gathered, even in environments where traditional desktop tools may not be practical. Finally, the tool generates a report that includes all relevant details and informative graphs. The proposed tool can be helpful in forensic investigations and is easily shareable or viewable on mobile devices.
A Mobile Forensic Tool for Enhancing Cyber-Physical Security by Detecting XSS Attacks Through Web Server Access Log Analysis
Pizzolante, Raffaele;Castiglione, Arcangelo;Mastroianni, Michele;Palmieri, Francesco
2025
Abstract
Cross-site scripting (XSS) attacks are a critical threat to Web applications. These attacks allow the injection of malicious scripts into trusted websites, which can lead to data theft, session hijacking, and the compromise of user accounts. In this paper, we propose a novel forensic analysis tool specifically designed for mobile devices, which enables investigators to efficiently analyze Web server access logs, which are critical forensic resources, to detect potential traces of XSS attacks. The mobile-first design ensures that essential forensic data can be quickly gathered, even in environments where traditional desktop tools may not be practical. Finally, the tool generates a report that includes all relevant details and informative graphs. The proposed tool can be helpful in forensic investigations and is easily shareable or viewable on mobile devices.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.