Analyzing the Feasibility of Adopting Google's Nonce-Based CSP Solutions on Websites
Mengxia Ren, Anhao Xiang, Chuan Yue
摘要
Content Security Policy (CSP) is a leading security mechanism for mitigating content injection attacks such as CrossSite Scripting (XSS). Nevertheless, despite efforts from academia and industry, CSP policies (in short, CSPs) are not widely deployed on websites, and deployed CSPs often have security issues or errors. Such low and insecure CSP deployment problems are mainly due to the complexity of the CSP mechanism. Google recently proposed four nonce-based CSP solutions which are simpler and more secure compared to traditional whitelisting-based CSP solutions. Google successfully deployed their nonce-based CSP solutions on over 160 services, covering 62% of all outgoing Google traffic. These nonce-based CSP solutions use simple CSPs but provide fine-grained control of web resources; therefore, if widely adopted on many other websites, they can be very helpful on addressing the low and insecure CSP deployment problems. In this paper, we evaluate the feasibility of adopting Google's nonce-based CSP solutions on the Tranco top 10K websites. We construct a crawling tool to automatically visit websites, simulate user interactions, and insert four CSPs to collect the CSP violations triggered under them. We investigate the adoptability of the nonce-based CSP solutions, adoption issues, and the stability of adopting them on websites by analyzing the CSP violations triggered under the inserted CSPs. We found that most websites can adopt the nonce-based CSP solutions on all their webpages visited in our study. For websites that cannot, usually the adoption is hard on around 40% of their webpages. Overall, our results are very encouraging and can be helpful in promoting the proper deployment of CSPs on many websites.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 被引用 114 次
- CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy CompositionStefano Calzavara, Alvise Rabitti, Michele BugliesiUSENIX Security 2017 · 被引用 15 次
- Complex Security Policy? A Longitudinal Analysis of Deployed Content Security PoliciesSebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis 等NDSS 2020
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 被引用 71 次
- CSPAutoGen: Black-box Enforcement of Content Security Policy upon Real-world WebsitesXiang Pan, Yinzhi Cao, Shuangping Liu, Yu Zhou 等CCS 2016 · 被引用 55 次
