首页> 外文会议>ICT systems security and privacy protection >On the Integrity of Cross-Origin JavaScripts
【24h】

On the Integrity of Cross-Origin JavaScripts

机译:关于跨源JavaScript的完整性

获取原文
获取原文并翻译 | 示例

摘要

The same-origin policy is a fundamental part of the Web. Despite the restrictions imposed by the policy, embedding of third-party JavaScript code is allowed and commonly used. Nothing is guaranteed about the integrity of such code. To tackle this deficiency, solutions such as the subresource integrity standard have been recently introduced. Given this background, this paper presents the first empirical study on the temporal integrity of cross-origin JavaScript code. According to the empirical results based on a ten day polling period of over 35 thousand scripts collected from popular websites, (ⅰ) temporal integrity changes are relatively common; (ⅱ) the adoption of the subresource integrity standard is still in its infancy; and (ⅲ) it is possible to statistically predict whether a temporal integrity change is likely to occur. With these results and the accompanying discussion, the paper contributes to the ongoing attempts to better understand security and privacy in the current Web.
机译:同源策略是Web的基本组成部分。尽管有该策略的限制,但仍允许并通常使用第三方JavaScript代码的嵌入。不能保证此类代码的完整性。为了解决该缺陷,最近引入了诸如子资源完整性标准的解决方案。在这种背景下,本文提出了关于跨源JavaScript代码的时间完整性的第一个实证研究。根据以十天的投票期为基础的实证结果,该民意调查是从流行网站中收集的超过35,000种脚本的(10)时间完整性变化相对普遍; (ⅱ)子资源完整性标准的采用仍处于起步阶段; (ⅲ)可以统计地预测时间完整性是否可能发生变化。通过这些结果和相关的讨论,本文有助于更好地了解当前Web中的安全性和隐私性的持续尝试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号