<?xml version='1.0' encoding='UTF-8'?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-05-11T13:15:43Z</responseDate>
  <request metadataPrefix="jpcoar_1.0" verb="GetRecord" identifier="oai:ipsj.ixsq.nii.ac.jp:00197521">https://ipsj.ixsq.nii.ac.jp/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:ipsj.ixsq.nii.ac.jp:00197521</identifier>
        <datestamp>2025-01-19T22:18:58Z</datestamp>
        <setSpec>1164:1579:9681:9819</setSpec>
      </header>
      <metadata>
        <jpcoar:jpcoar xmlns:datacite="https://schema.datacite.org/meta/kernel-4/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcndl="http://ndl.go.jp/dcndl/terms/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:jpcoar="https://github.com/JPCOAR/schema/blob/master/1.0/" xmlns:oaire="http://namespace.openaire.eu/schema/oaire/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:rioxxterms="http://www.rioxx.net/schema/v2.0/rioxxterms/" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns="https://github.com/JPCOAR/schema/blob/master/1.0/" xsi:schemaLocation="https://github.com/JPCOAR/schema/blob/master/1.0/jpcoar_scm.xsd">
          <dc:title>動的情報フロー追跡を用いた反射型XSSの検出</dc:title>
          <dc:title xml:lang="en">Detection of Reflected XSS by Using Dynamic Information Flow Tracking</dc:title>
          <jpcoar:creator>
            <jpcoar:creatorName>塚本, 駿佑</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:creator>
            <jpcoar:creatorName>坂井, 修一</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:creator>
            <jpcoar:creatorName>入江, 英嗣</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:creator>
            <jpcoar:creatorName xml:lang="en">Shunsuke, Tsukamoto</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:creator>
            <jpcoar:creatorName xml:lang="en">Shuichi, Sakai</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:creator>
            <jpcoar:creatorName xml:lang="en">Hidetsugu, Irie</jpcoar:creatorName>
          </jpcoar:creator>
          <jpcoar:subject subjectScheme="Other">セキュリティ・高信頼技術</jpcoar:subject>
          <datacite:description descriptionType="Other">XSS Auditor に代表される XSS フィルタリング機能は反射型 XSS 攻撃をクライアントサイドで検出する機能だが，文字列比較による既存の検出アルゴリズムでは偽陽性誤検出を防げず，この誤検出による特有の脆弱性が存在する．つまり，XSS Auditor のブラウザヘの実装は，反射型 XSS への耐性を強化する一方で，Universal XSS や情報窃取といった別の種類の攻撃の要因となる．偽陽性誤検出の原因はサーバでどのようにデータが使われるのかをクライアントが知ることができないことである．そこで，本論文ではサーバでのデータの流れを追跡し結果をクライアントに伝達することによって，原理的に偽陽性誤検出が発生せず，それに起因する特有の脆弱性を持たない反射型 XSS の検出手法を提案する．</datacite:description>
          <datacite:description descriptionType="Other">XSS Auditor is a system that detects reflected XSS attacks in the client side. While it enhances resistance against reflected XSS, it also causes other types of security vulnerability, such as Universal XSS or information leak, because of false positives that structurally cannot be avoided. This article proposes a system that detects reflected XSS with almost no false positives. It is achieved by the server application to track the flow of data which is sent from the client and feed back the result to the client. The experiment shows that the proposed method is able to detect reflected XSS attacks at the same accuracy as the existing system without false positives.</datacite:description>
          <dc:publisher xml:lang="ja">情報処理学会</dc:publisher>
          <datacite:date dateType="Issued">2019-06-04</datacite:date>
          <dc:language>jpn</dc:language>
          <dc:type rdf:resource="http://purl.org/coar/resource_type/c_18gh">technical report</dc:type>
          <jpcoar:identifier identifierType="URI">https://ipsj.ixsq.nii.ac.jp/records/197521</jpcoar:identifier>
          <jpcoar:sourceIdentifier identifierType="ISSN">2188-8574</jpcoar:sourceIdentifier>
          <jpcoar:sourceIdentifier identifierType="NCID">AN10096105</jpcoar:sourceIdentifier>
          <jpcoar:sourceTitle>研究報告システム・アーキテクチャ（ARC）</jpcoar:sourceTitle>
          <jpcoar:volume>2019-ARC-236</jpcoar:volume>
          <jpcoar:issue>15</jpcoar:issue>
          <jpcoar:pageStart>1</jpcoar:pageStart>
          <jpcoar:pageEnd>6</jpcoar:pageEnd>
          <jpcoar:file>
            <jpcoar:URI label="IPSJ-ARC19236015.pdf">https://ipsj.ixsq.nii.ac.jp/record/197521/files/IPSJ-ARC19236015.pdf</jpcoar:URI>
            <jpcoar:mimeType>application/pdf</jpcoar:mimeType>
            <jpcoar:extent>404.4 kB</jpcoar:extent>
          </jpcoar:file>
        </jpcoar:jpcoar>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
