A Measurement Study of the Content Security Policy on Real-World Applications
نویسندگان
چکیده
Content Security Policy (CSP) is a browser security mechanism that aims to protect websites from content injection attacks. To adopt CSP, website developers need to manually compile a list of allowed content sources. Nearly all websites require modifications to comply with CSP’s default behavior, which blocks inline scripts and the use of the eval() function. Alternatively, websites could adopt a policy that allows the use of this unsafe functionality, but this opens up potential attack vectors. In this paper, our measurements on a large corpus of web applications provide a key insight on the amount of efforts web developers required to adapt to CSP. Our results also identified errors in CSP policies that are set by website developers on their websites. To address these issues and make adoption of CSP easier and error free, we implemented UserCSP a tool as a Firefox extension. The UserCSP uses dynamic analysis to automatically infer CSP policies, facilitates testing, and gives savvy users the authority to enforce client-side policies on websites.
منابع مشابه
Comparative Advantage, Self-sufficiency and Food Security in Iran: Case Study of Wheat Commodity
Food security has a dynamic notion during the time and may be affected by various domestic and global factors.Nevertheless, Iranian policy makers consider food security as same as self-sufficiency in agricultural food products, particularly wheat production. However, self-sufficiency can contribute to food security only if it is in coincidences with comparative advantage and sustainable resourc...
متن کاملThe Challenges and Trends of Deploying Blockchain in the Real World for the Users’ Need
Blockchain technology is a decentralized and open database maintained by a peer-to-peer network, offering a “trustless trust” for untrusted parties. Despite the fact that some researchers consider blockchain as a bubble, blockchain technology has the genuine potential to solve problems across industries. In this article, we provide an overview of the development that Blockchain technology has h...
متن کاملIran’s Foreign Policy Approaches toward International Organizations
Iran’s foreign policy toward international organizations has always oscillated between divergence and convergence, depending on the status of the country in question and the statesmen's point of the view. This study aimed to examine the status of international organizations in Iran’s foreign policy. A divergent approach to international organizations was adopted during 1981-1988 and 2005-2013. ...
متن کاملInvestigate the Quality of Social Security Organization Policy-Making on Social Security Pensioners Life Style Changes
This article has been done with aims to investigate impact of the quality of social security organization policy-making on pensioners' life style in that organization in the city of Mahabad and based on the criteria of environmental, Economic, Social, Political, Health, Personal security, life expectancy, housing and other services have been research case that are the most important factors tha...
متن کاملتأثیر ایدئولوژی بر منافع ملی و امنیت ملی در سیاست خارجی جمهوری اسلامی ایران: با تاکید بر اندیشه امام خمینی(ره)
The Islamic Revolution of 1979 in Iran, led by Imam Khomeini as a religious authority, helped establish a political order whose domestic and foreign policy was based on Islamic ideology. The aim of this study was to investigate Imam Khomeini’s discourse of foreign policy in relation to national interests and security, and Islamic ideology on three levels, namely, ideology, strategy, and diploma...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- I. J. Network Security
دوره 18 شماره
صفحات -
تاریخ انتشار 2016