An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources
Bertil Chapuis, Olamide Omolola, Mauro Cherubini, Mathias Humbert, Kévin Huguenin
摘要
Web developers can (and do) include subresources such as scripts, stylesheets and images in their webpages. Such subresources might be stored on content delivery networks (CDNs). This practice creates security and privacy risks, should a subresource be corrupted. The subresource integrity (SRI) recommendation, released in mid-2016 by the W3C, enables developers to include digests in their webpages in order for web browsers to verify the integrity of subresources before loading them. In this paper, we conduct the rst large-scale longitudinal study of the use of SRI on the Web by analyzing massive crawls (⇡3B URLs) of the Web over the last 3.5 years. Our results show that the adoption of SRI is modest (⇡3.40%), but grows at an increasing rate and is highly inuenced by the practices of popular library developers (e.g., Bootstrap) and CDN operators (e.g., jsDelivr). We complement our analysis about SRI with a survey of web developers (# =227): It shows that a substantial proportion of developers know SRI and understand its basic functioning, but most of them ignore important aspects of the recommendation. The results of the survey also show that the integration of SRI by developers is mostly manual -hence not scalable and error prone. This calls for a better integration of SRI in build tools. CCS CONCEPTS • Security and privacy → Web protocol security; Hash functions and message authentication codes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 被引用 56 次
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 被引用 7 次
- An Empirical Study of the Usage of Checksums for Web DownloadsGaël Bernard, Rémi Coudert, Bertil Chapuis, Kévin HugueninWWW 2023 · 被引用 1 次
- What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management SystemJohnny So, Michael Ferdman, Nick NikiforakisCCS 2025
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
它引用的顶会 Paper6
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson 等NDSS 2017 · 被引用 183 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 等S&P 2019 · 被引用 105 次
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien 等S&P 2019 · 被引用 44 次
相关 Paper
- Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the MassesMauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert 等CCS 2018 · 被引用 11 次
- Reining in the Web's Inconsistencies with Site PolicyStefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens 等NDSS 2021
- Keys on Doormats: Exposed API Credentials on the WebNurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir DurumericCCS 2026 · 被引用 2 次
- We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORSJianjun Chen, Jian Jiang, Hai-Xin Duan, Tao Wan 等USENIX Security 2018 · 被引用 30 次
- The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite CookiesSoheil Khodayari, Giancarlo PellegrinoS&P 2022 · 被引用 28 次
