首页> 外文期刊>ACM transactions on the web >Semantics-Based Analysis of Content Security Policy Deployment
【24h】

Semantics-Based Analysis of Content Security Policy Deployment

机译:基于语义的内容安全策略部署分析

获取原文
获取原文并翻译 | 示例

摘要

Content Security Policy (CSP) is a recent W3C standard introduced to prevent and mitigate the impact of content injection vulnerabilities on websites. In this article, we introduce a formal semantics for the latest stable version of the standard, CSP Level 2. We then perform a systematic, large-scale analysis of the effectiveness of the current CSP deployment, using the formal semantics to substantiate our methodology and to assess the impact of the detected issues. We focus on four key aspects that affect the effectiveness of CSP: browser support, website adoption, correct configuration, and constant maintenance. Our analysis shows that browser support for CSP is largely satisfactory, with the exception of a few notable issues. However, there are several shortcomings relative to the other three aspects. CSP appears to have a rather limited deployment as yet and, more crucially, existing policies exhibit a number of weaknesses and misconfiguration errors. Moreover, content security policies are not regularly updated to ban insecure practices and remove unintended security violations. We argue that many of these problems can be fixed by better exploiting the monitoring facilities of CSP, while other issues deserve additional research, being more rooted into the CSP design.
机译:内容安全策略(CSP)是最新的W3C标准,旨在防止和减轻内容注入漏洞对网站的影响。在本文中,我们为标准的最新稳定版本CSP Level 2引入形式语义。然后,我们使用形式语义来证实我们的方法和方法,对当前CSP部署的有效性进行系统的大规模分析。评估发现的问题的影响。我们关注影响CSP有效性的四个关键方面:浏览器支持,网站采用,正确的配置和持续的维护。我们的分析表明,浏览器对CSP的支持在很大程度上令人满意,除了一些值得注意的问题。但是,相对于其他三个方面,存在一些缺点。 CSP的部署似乎还很有限,更重要的是,现有策略存在许多弱点和配置错误。此外,内容安全策略不会定期更新以禁止不安全的做法并消除意外的安全违规。我们认为,可以通过更好地利用CSP的监视工具来解决许多问题,而其他问题则需要进一步研究,更多地植根于CSP设计中。

著录项

  • 来源
    《ACM transactions on the web》 |2018年第2期|10.1-10.36|共36页
  • 作者单位

    Univ Ca Foscari Venezia, Dipartimento Sci Ambientali Informat & Stat, Via Torino 155, I-30170 Venice, Italy;

    Univ Ca Foscari Venezia, Dipartimento Sci Ambientali Informat & Stat, Via Torino 155, I-30170 Venice, Italy;

    Univ Ca Foscari Venezia, Dipartimento Sci Ambientali Informat & Stat, Via Torino 155, I-30170 Venice, Italy;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Content security policy; formal methods; web security;

    机译:内容安全策略;正式方法;网络安全;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号