The More Things Change, the More They Stay the Same: Integrity of Modern JavaScript
Johnny So, Michael Ferdman, Nick Nikiforakis
Abstract
The modern web is a collection of remote resources that are identified by their location and composed of interleaving networks of trust. Supply chain attacks compromise the users of a target domain by leveraging its often large set of trusted third parties who provide resources such as JavaScript. The ubiquity of JavaScript, paired with its ability to execute arbitrary code on client machines, makes this particular web resource an ideal vector for supply chain attacks. Currently, there exists no robust method for users browsing the web to verify that the script content they receive from a third party is the expected content. In this paper, we present key insights to inform the design of robust integrity mechanisms, derived from our large-scale analyses of the 6M scripts we collected while crawling 44K domains every day for 77 days. We find that scripts that frequently change should be considered first-class citizens in the modern web ecosystem, and that the ways in which scripts change remain constant over time. Furthermore, we present analyses on the use of strict integrity verification (e.g., Subresource Integrity) at the granularity of the script providers themselves, offering a more complete perspective and demonstrating that the use of strict integrity alone cannot provide satisfactory security guarantees. We conclude that it is infeasible for a client to distinguish benign changes from malicious ones without additional, external knowledge, motivating the need for a new protocol to provide clients the necessary context to assess the potential ramifications of script changes. CCS CONCEPTS • Security and privacy → Web protocol security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19908ce1-e8c3-4445-926a-62c45f626c72Cited by top-tier papers5
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 17 citations
- The Times They Are A-Changin': Characterizing Post-Publication Changes to Online NewsChris Tsoukaladelis, Brian Kondracki, Niranjan Balasubramanian, Nick NikiforakisS&P 2024 · 2 citations
- What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management SystemJohnny So, Michael Ferdman, Nick NikiforakisCCS 2025
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- Web Execution Bundles: Reproducible, Accurate, and Archivable Web MeasurementsFlorian Hantke, Peter Snyder, Hamed Haddadi, Ben StockUSENIX Security 2025
Builds on6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Beyond the Front Page: Measuring Third Party Dynamics in the FieldTobias Urban, Martin Degeling, Thorsten Holz, Norbert PohlmannWWW 2020 · 77 citations
- Reproducibility and Replicability of Web Measurement StudiesNurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger et al.WWW 2022 · 47 citations
- Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript SignaturesQuan Chen, Peter Snyder, Ben Livshits, Alexandros KapravelosS&P 2021 · 33 citations
- An Empirical Study of the Use of Integrity Verification Mechanisms for Web SubresourcesBertil Chapuis, Olamide Omolola, Mauro Cherubini, Mathias Humbert et al.WWW 2020 · 13 citations
Related papers
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the WebJan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein et al.CCS 2025
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- Detecting and understanding JavaScript global identifier conflicts on the webMingxue Zhang, Wei MengFSE 2020 · 10 citations
