AutoNav: Evaluation and Automatization of Web Navigation Policies
Benjamin Eriksson, Andrei Sabelfeld
Abstract
Undesired navigation in browsers powers a significant class of attacks on web applications. In a move to mitigate risks associated with undesired navigation, the security community has proposed a standard that gives control to web pages to restrict navigation. The standard draft introduces a new navigate-to directive of the Content Security Policy (CSP). The directive is currently being implemented by mainstream browsers. This paper is a first evaluation of navigate-to, focusing on security, performance, and automatization of navigation policies. We present new vulnerabilities introduced by the directive into the web ecosystem, opening up for attacks such as probing to detect if users are logged in to other websites or have active shopping carts, bypassing third-party cookie blocking, exfiltrating secrets, as well as leaking browsing history. Unfortunately, the directive triggers vulnerabilities even in websites that do not use the directive in their policies. We identify both specificationand implementation-level vulnerabilities and propose countermeasures to mitigate both. To aid developers in configuring navigation policies, we develop and implement AutoNav 1 , an automated blackbox mechanism to infer navigation policies. AutoNav leverages the benefits of origin-wide policies in order to improve security without degrading performance. We evaluate the viability of navigate-to and AutoNav by an empirical study on Alexa's top 10,000 websites. CCS Concepts • Security and privacy → Web application security;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web BrowsersLukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor Noß et al.CCS 2021 · 11 citations
- Reining in the Web's Inconsistencies with Site PolicyStefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens et al.NDSS 2021
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock et al.NDSS 2023
Builds on7
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Tracing Information Flows Between Ad Exchanges Using Retargeted AdsMuhammad Ahmad Bashir, Sajjad Arshad, William K. Robertson, Christo WilsonUSENIX Security 2016 · 132 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising InterfaceGiridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove et al.S&P 2018 · 110 citations
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
Related papers
- CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy CompositionStefano Calzavara, Alvise Rabitti, Michele BugliesiUSENIX Security 2017 · 15 citations
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes et al.USENIX Security 2020
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 71 citations
- Analyzing the Feasibility of Adopting Google's Nonce-Based CSP Solutions on WebsitesMengxia Ren, Anhao Xiang, Chuan YueICSE 2025 · 1 citation
