Reining in the Web's Inconsistencies with Site Policy
Stefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens, Ben Stock
摘要
Over the years, browsers have adopted an ever-increasing number of client-enforced security policies deployed by means of HTTP headers. Such mechanisms are fundamental for web application security, and usually deployed on a per-page basis. This, however, enables inconsistencies, as different pages within the same security boundaries (in form of origins or sites) can express conflicting security requirements. In this paper, we formalize inconsistencies for cookie security attributes, CSP and HSTS, and then quantify the magnitude and impact of inconsistencies at scale by crawling 15,000 popular sites. We show numerous sites endanger their own security by omission or misconfiguration of the aforementioned mechanisms, which lead to unnecessary exposure to XSS, cookie theft and HSTS deactivation. We then use our data to analyse to which extent the recent Origin Policy proposal can fix the problem of inconsistencies. Unfortunately, we conclude that the current Origin Policy design suffers from major shortcomings which limit its practical applicability to address security inconsistencies, while catering to the need of real-world sites. Based on these insights, we propose Site Policy, designed to overcome Origin Policy’s shortcomings and make any insecurity explicit. We make a prototype implementation of Site Policy publicly available, along with a support toolchain for initial policy generation, security analysis, and test deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite CookiesSoheil Khodayari, Giancarlo PellegrinoS&P 2022 · 被引用 28 次
- Automatic Discovery of Emerging Browser Fingerprinting TechniquesJunhua Su, Alexandros KapravelosWWW 2023 · 被引用 17 次
- Rise of Inspectron: Automated Black-box Auditing of Cross-platform Electron AppsMir Masood Ali, Mohammad Ghasemisharif, Chris Kanich, Jason PolakisUSENIX Security 2024 · 被引用 2 次
- The Security Lottery: Measuring Client-Side Web Security InconsistenciesSebastian Roth, Stefano Calzavara, Moritz Wilhelm, Alvise Rabitti 等USENIX Security 2022
- The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebJannis Rautenstrauch, Giancarlo Pellegrino, Ben StockS&P 2023
它引用的顶会 Paper13
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 被引用 114 次
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 被引用 86 次
- Beyond the Front Page: Measuring Third Party Dynamics in the FieldTobias Urban, Martin Degeling, Thorsten Holz, Norbert PohlmannWWW 2020 · 被引用 77 次
相关 Paper
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes 等USENIX Security 2020
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 被引用 71 次
- Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersJannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben StockCCS 2025
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock 等NDSS 2023
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
