USENIX Security2017Top-tier venue
CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy Composition
Stefano Calzavara, Alvise Rabitti, Michele Bugliesi
Abstract
Content Security Policy (CSP) is a W3C standard designed to prevent and mitigate the impact of content injection vulnerabilities on websites by means of browserenforced security policies. Though CSP is gaining a lot of popularity in the wild, previous research questioned one of its key design choices, namely the use of static white-lists to define legitimate content inclusions. In this paper we present Compositional CSP (CCSP), an extension of CSP based on runtime policy composition. CCSP is designed to overcome the limitations arising from the use of static white-lists, while avoiding a major overhaul of CSP and the logic underlying policy writing. We perform an extensive evaluation of the design of CCSP by focusing on the general security guarantees it provides, its backward compatibility and its deployment cost. We then assess the potential impact of CCSP on the web and we implement a prototype of our proposal, which we test on major websites. In the end, we conclude that the deployment of CCSP can be done with limited efforts and would lead to significant benefits for the large majority of the websites.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eba88b34-0126-4576-8386-b536ce2a0e32Cited by top-tier papers5
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- Moderator: Moderating Text-to-Image Diffusion Models through Fine-grained Context-based PoliciesPeiran Wang, Qiyu Li, Longxuan Yu, Ziyao Wang et al.CCS 2024 · 2 citations
- MatriXSSed: A New Taxonomy for XSS in the Modern WebDolière Francis SoméWWW 2025 · 2 citations
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock et al.NDSS 2023
- Complex Security Policy? A Longitudinal Analysis of Deployed Content Security PoliciesSebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis et al.NDSS 2020
Builds on3
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 71 citations
- CSPAutoGen: Black-box Enforcement of Content Security Policy upon Real-world WebsitesXiang Pan, Yinzhi Cao, Shuangping Liu, Yu Zhou et al.CCS 2016 · 55 citations
Related papers
- Analyzing the Feasibility of Adopting Google's Nonce-Based CSP Solutions on WebsitesMengxia Ren, Anhao Xiang, Chuan YueICSE 2025 · 1 citation
- 12 Angry Developers - A Qualitative Study on Developers' Struggles with CSPSebastian Roth, Lea Gröber, Michael Backes, Katharina Krombholz et al.CCS 2021 · 22 citations
- Fine-Grained Data-Centric Content Protection Policy for Web ApplicationsZilun Wang, Wei Meng, Michael R. LyuCCS 2023 · 2 citations
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes et al.USENIX Security 2020
- Reining in the Web's Inconsistencies with Site PolicyStefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens et al.NDSS 2021
