...
首页> 外文期刊>SN Applied Sciences >JSSignature: eliminating third‑party‑hosted JavaScript infection threats using digital signatures
【24h】

JSSignature: eliminating third‑party‑hosted JavaScript infection threats using digital signatures

机译:JSSignature:使用数字签名消除第三方托管的JavaScript感染威胁

获取原文
获取原文并翻译 | 示例
           

摘要

Today, third-party JavaScript resources are an indispensable part of the web platform. More than 88% of the world’stop websites include at least one JavaScript resource from a remote host. However, there is a great security risk behindusing a third-party JavaScript resource, if an attacker can infect one of these remote JavaScript resources all websitesthose have included the script would be at risk. In this paper, we present JSSignature, an entirely at the client-side pureJavaScript framework in order to validate third-party JavaScript resources using a digital signature. Therefore, all includedJavaScript resources are checked against the integrity, authentication and non-repudiation risks before the execution. Incontrary to existing methods, JSSignature protects web pages regardless of third-party resource infection nature whileit does not set any restrictions on trusted JavaScript providers. This approach has an acceptable one-time performanceoverhead and is an easily deployable add-in. We have validated the proposed solution by applying tests on an implementedversion (https ://iasbs .ac.ir/~ansar i/jssig natur e/demo.html). A pre-published version of this paper is available atarXiv website (https ://arxiv .org/pdf/1812.03939 .pdf ).
机译:如今,第三方JavaScript资源已成为Web平台不可或缺的一部分。超过88%的世界热门网站至少包含一个来自远程主机的JavaScript资源。但是,背后存在巨大的安全风险如果攻击者可以感染所有网站的这些远程JavaScript资源之一,则使用第三方JavaScript资源那些包含脚本的网站将处于危险之中。在本文中,我们介绍了JSSignature,它完全在客户端JavaScript框架,以便使用数字签名来验证第三方JavaScript资源。因此,全部包括在执行之前,将检查JavaScript资源的完整性,身份验证和不可否认性风险。在与现有方法相反,无论第三方资源受感染的性质如何,JSSignature都会保护网页它对可信任的JavaScript提供程序没有设置任何限制。这种方法具有可接受的一次性性能开销,并且是易于部署的加载项。我们已通过对已实施的应用程序进行测试来验证了建议的解决方案版本(https://iasbs.ac.ir/~ansar i / jssig natur e / demo.html)。本文的预发布版本可在以下位置获得:arXiv网站(https://arxiv.org/pdf/1812.03939.pdf)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号