If It's Not Secure, It Should Not Compile: Preventing DOM-Based XSS in Large-Scale Web Development with API Hardening
Pei Wang, Julian Bangert, Christoph Kern
Abstract
With tons of efforts spent on its mitigation, Cross-site scripting (XSS) remains one of the most prevalent security threats on the internet. Decades of exploitation and remediation demonstrated that code inspection and testing alone does not eliminate XSS vulnerabilities in complex web applications with a high degree of confidence. This paper introduces Google's secure-by-design engineering paradigm that effectively prevents DOM-based XSS vulnerabilities in large-scale web development. Our approach, named API hardening, enforces a series of company-wide secure coding practices. We provide a set of secure APIs to replace native DOM APIs that are prone to XSS vulnerabilities. Through a combination of type contracts and appropriate validation and escaping, the secure APIs ensure that applications based thereon are free of XSS vulnerabilities. We deploy a simple yet capable compile-time checker to guarantee that developers exclusively use our hardened APIs to interact with the DOM. We make various of efforts to scale this approach to tens of thousands of engineers without significant productivity impact. By offering rigorous tooling and consultant support, we help developers adopt the secure coding practices as seamlessly as possible. We present empirical results showing how API hardening has helped reduce the occurrences of XSS vulnerabilities in Google's enormous code base over the course of two-year deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Unhelpful Assumptions in Software Security ResearchIta Ryan, Utz Roedig, Klaas-Jan StolCCS 2023 · 9 citations
- TranSPArent: Taint-style Vulnerability Detection in Generic Single Page Applications through Automated Framework AbstractionSenapati Diwangkara, Yinzhi CaoNDSS 2026 · 1 citation
Builds on7
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes et al.CCS 2017 · 125 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
- Towards Memory Safe Enclave Programming with Rust-SGXHuibo Wang, Pei Wang, Yu Ding, Mingshen Sun et al.CCS 2019 · 86 citations
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
Related papers
- Trust Me If You Can - How Usable Is Trusted Types In Practice?Sebastian Roth, Lea Gröber, Philipp Baus, Katharina Krombholz et al.USENIX Security 2024 · 3 citations
- Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script GadgetsSebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava et al.CCS 2017 · 62 citations
- Analyzing the Feasibility of Adopting Google's Nonce-Based CSP Solutions on WebsitesMengxia Ren, Anhao Xiang, Chuan YueICSE 2025 · 1 citation
- Complex Security Policy? A Longitudinal Analysis of Deployed Content Security PoliciesSebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis et al.NDSS 2020
- ScriptChecker: To Tame Third-party Script Execution With Task CapabilitiesWu Luo, Xuhua Ding, Pengfei Wu, Xiaolei Zhang et al.NDSS 2022
