A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy Bugs
Gertjan Franken, Tom van Goethem, Lieven Desmet, Wouter Joosen
摘要
The constantly evolving Web exerts a chronic pressure on the development and maintenance of the Content Security Policy (CSP), which stands as one of the primary security policies to mitigate attacks such as cross-site scripting. Indeed, to attain comprehensiveness, the policy must account for virtually every newly introduced browser feature, and every existing browser feature must be scrutinized upon extension of CSP functionality. Unfortunately, this undertaking's complexity has already led to critical implementational shortcomings, resulting in the security subversion of all CSP-employing websites. In this paper, we present the first systematic analysis of CSP bug lifecycles, shedding new light on bug root causes. As such, we leverage our automated framework, BUGHOG, to evaluate the reproducibility of publicly disclosed bug proofs of concept in over 100, 000 browser revisions. By considering the entire source code revision history since the introduction of CSP for Chromium and Firefox, we identified 123 unique introducing and fixing revisions for 75 CSP bugs. Our analysis shows that inconsistent handling of bugs led to the early public disclosure of three, and that the lifetime of several others could have been considerably decreased through adequate bug sharing between vendors. Finally, we propose solutions to improve current bug handling and response practices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User InterfaceMingi Jung, Donggyu Kim, Mijung Kim, Seongil WiUSENIX Security 2026
- Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersJannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben StockCCS 2025
它引用的顶会 Paper16
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 被引用 228 次
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang 等S&P 2020 · 被引用 126 次
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 被引用 114 次
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 被引用 71 次
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 被引用 52 次
相关 Paper
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock 等NDSS 2023
- Complex Security Policy? A Longitudinal Analysis of Deployed Content Security PoliciesSebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis 等NDSS 2020
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes 等USENIX Security 2020
- Reining in the Web's Inconsistencies with Site PolicyStefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens 等NDSS 2021
- CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy CompositionStefano Calzavara, Alvise Rabitti, Michele BugliesiUSENIX Security 2017 · 被引用 15 次
