Fine-Grained Data-Centric Content Protection Policy for Web Applications
Zilun Wang, Wei Meng, Michael R. Lyu
Abstract
The vast amount of sensitive data in modern web applications has become a prime target for cyberattacks. Existing browser security policies disallow the execution of unknown scripts but do not restrict access to sensitive web content by "trusted" third-party scripts. Prior works have observed that over-privileged third-party scripts can compromise the confidentiality and integrity of sensitive user data in the applications, which introduces vital security issues to web applications.
This paper proposes Content Protection Policy (CPP), a new web security mechanism for providing fine-grained confidentiality and integrity protection for sensitive client-side user data. It enables object-level protection instead of page-level protection by taking a data-centric design approach. A policy specifies the access permission of each script on individual sensitive elements. Any unauthorized access is denied by default to achieve the least privilege in the browser.
We implemented a prototype system-DOMinator-to enforce the content protection policies in the browser, and an extensionpolicy generator-to help web developers write basic policy rules. We thoroughly evaluated it with popular websites and showed that it could effectively protect sensitive web content with a low performance overhead and great usability. CPP complements existing security mechanisms and provides web developers with a more flexible way to protect sensitive data, which can further mitigate the impact of content injection attacks and significantly improve the security of web applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Moderator: Moderating Text-to-Image Diffusion Models through Fine-grained Context-based PoliciesPeiran Wang, Qiyu Li, Longxuan Yu, Ziyao Wang et al.CCS 2024 · 2 citations
- DOM-XSS Detection via Webpage Interaction Fuzzing and URL Component SynthesisNuno Sabino, Darion Cassel, Rui Abreu, Pedro Adão et al.NDSS 2026 · 1 citation
- CASPR: Context-Aware Security Policy RecommendationLifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao et al.NDSS 2025
Builds on5
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- All Your Clicks Belong to Me: Investigating Click Interception on the WebMingxue Zhang, Wei Meng, Sangho Lee, Byoungyoung Lee et al.USENIX Security 2019 · 26 citations
- JSISOLATE: lightweight in-browser JavaScript isolationMingxue Zhang, Wei MengFSE 2021 · 9 citations
- Leaky Forms: A Study of Email and Password Exfiltration Before Form SubmissionAsuman Senol, Gunes Acar, Mathias Humbert, Frederik J. Zuiderveen BorgesiusUSENIX Security 2022
Related papers
- Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebRui ZhaoWWW 2025 · 2 citations
- CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy CompositionStefano Calzavara, Alvise Rabitti, Michele BugliesiUSENIX Security 2017 · 15 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Least Privilege Access for Persistent Storage Mechanisms in Web BrowsersGayatri Priyadarsini Kancherla, Dishank Goel, Abhishek BichhawatWWW 2025 · 2 citations
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock et al.NDSS 2023
