Research on the Effectiveness of Sanitization Libraries for XSS Attacks in Web Applications

Sokolov, V. Y. and Polikovskyi, Bogdan and Vorokhob, Maksym and Tsyrul, Oleksandr (2025) Research on the Effectiveness of Sanitization Libraries for XSS Attacks in Web Applications Кібербезпека: освіта, наука, техніка, 31 (3). pp. 801-819. ISSN 2412-4338

[thumbnail of V_Sokolov_B_Polikovskyi_M_Vorokhob_O_Tsyrul_CEST_3_31.pdf] Text
V_Sokolov_B_Polikovskyi_M_Vorokhob_O_Tsyrul_CEST_3_31.pdf - Published Version

Download (809kB)

Abstract

Cross-Site Scripting (XSS) attacks remain one of the most prevalent and critical vulnerabilities in modern web applications, as they allow attackers to execute arbitrary malicious code in the user’s browser, compromising confidentiality, integrity, and availability of data. One of the key approaches to mitigating XSS is the use of sanitization libraries designed to clean or safely transform user input before it is processed and rendered. This article presents a comprehensive experimental study of the effectiveness of popular HTML sanitization libraries in the context of protecting web applications against XSS attacks. A specialized dataset of 100 unique XSS vectors is proposed and utilized, covering both classical attack scenarios (script tags, event handlers) and modern, less obvious techniques, including CSS injections, SVG-based vectors, DOM clobbering, encoded payloads, and abuse of contemporary browser APIs. To conduct the experiments, an automated testing framework based on Node.js and browser emulation tools was developed, enabling realistic reproduction of malicious code execution conditions. A comparative analysis of DOMPurify, js-xss, sanitize-html, and OWASP Java HTML Sanitizer was performed using their default configurations and evaluated according to XSS blocking rate, performance, and memory consumption, as well as through a multi-criteria assessment considering security, maintainability, and practical applicability. The experimental results demonstrate that none of the analyzed libraries provides complete out-of-the-box protection, while a common weakness across all solutions is vulnerability to DOM clobbering and encoded attack vectors. Based on the findings, practical recommendations are formulated regarding the configuration and deployment of sanitization libraries as part of a defense-in-depth strategy for modern web applications.

Item Type: Article
Uncontrolled Keywords: XSS attacks; cross-site scripting; web security; data sanitization; Content Security Policy; input validation; DOM-based XSS; cybersecurity; web application protection
Subjects: Статті у періодичних виданнях > Фахові (входять до переліку фахових, затверджений МОН)
Divisions: Це архівні підрозділи Київського університету імені Бориса Грінченка > Факультет інформаційних технологій та математики > Кафедра інформаційної та кібернетичної безпеки імені професора Володимира Бурячка
Depositing User: Volodymyr Sokolov
Date Deposited: 25 Dec 2025 13:39
Last Modified: 25 Dec 2025 13:39
URI: https://elibrary.kubg.edu.ua/id/eprint/55479

Actions (login required)

View Item View Item