【24h】

On the Integrity of Cross-Origin JavaScripts

机译:论跨起轨JavaScript的完整性

获取原文

摘要

The same-origin policy is a fundamental part of the Web. Despite the restrictions imposed by the policy, embedding of third-party JavaScript code is allowed and commonly used. Nothing is guaranteed about the integrity of such code. To tackle this deficiency, solutions such as the subresource integrity standard have been recently introduced. Given this background, this paper presents the first empirical study on the temporal integrity of cross-origin JavaScript code. According to the empirical results based on a ten day polling period of over 35 thousand scripts collected from popular websites, (ⅰ) temporal integrity changes are relatively common; (ⅱ) the adoption of the subresource integrity standard is still in its infancy; and (ⅲ) it is possible to statistically predict whether a temporal integrity change is likely to occur. With these results and the accompanying discussion, the paper contributes to the ongoing attempts to better understand security and privacy in the current Web.
机译:同样原始策略是网络的基本部分。尽管政策施加了限制,但允许嵌入第三方JavaScript代码并常用。没有任何东西可以保证这种代码的完整性。为了解决这个缺陷,最近已经介绍了诸如子资源完整性标准的解决方案。鉴于此背景,本文介绍了对跨原因JavaScript代码的时间完整性的第一个实证研究。根据从流行网站收集的超过35万脚本的十天投票期的经验结果,(Ⅰ)时间完整性变化相对普遍; (Ⅱ)采用子源完整标准仍处于起步阶段; (Ⅲ)可以统计上预测是否可能发生时间完整性变化。通过这些结果和随附的讨论,本文有助于正在进行的尝试更好地了解当前网络中的安全和隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号