Publication Type
Journal Article
Version
publishedVersion
Publication Date
3-2022
Abstract
To mitigate cross-site scripting attacks (XSS), the W3C group recommends web service providers to employ a computer security standard called Content Security Policy (CSP). However, less than 3.7 percent of real-world websites are equipped with CSP according to Google’s survey. The low scalability of CSP is incurred by the difficulty of deployment and non-compatibility for state-of-art browsers. To explore the scalability of CSP, in this article, we propose JavaScript based CSP (JSCSP), which is able to support most of real-world browsers but also to generate security policies automatically. Specifically, JSCSP offers a novel self-defined security policy which enforces essential confinements to related items, including JavaScript functions, DOM elements and data access. Meanwhile, JSCSP has an efficient algorithm to automatically generate the policy directives and enforce them in a cascading way, which is more fine-grained and practical than the functionalities provided by CSP. We further implement JSCSP on a Chrome extension, and our evaluation shows that the extension is compatible with popular JavaScript libraries. Our JSCSP extension can detect and block the tested attacking vectors extracted from the prevalent web applications. We state that JSCSP delivers better performance compared to other XSS defense solutions.
Keywords
Cross-site scripting attacks, content security policy, origin confinement, JavaScript sandbox, cookie protection
Discipline
Programming Languages and Compilers | Software Engineering
Research Areas
Software and Cyber-Physical Systems
Publication
IEEE Transactions on Dependable and Secure Computing
Volume
19
Issue
2
First Page
862
Last Page
878
ISSN
1545-5971
Identifier
10.1109/TDSC.2020.3009472
Publisher
Institute of Electrical and Electronics Engineers
Citation
XU, Guangquan; XIE, Xiaofei; HUANG, Shuhan; ZHANG, Jun; PAN, Lei; LOU, Wei; and LIANG, Kaitai.
JSCSP: A novel policy-based XSS defense mechanism for browsers. (2022). IEEE Transactions on Dependable and Secure Computing. 19, (2), 862-878.
Available at: https://ink.library.smu.edu.sg/sis_research/7083
Creative Commons License
This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.