arrow
返回

Client-side cross-site scripting protection

delete2009-10-01
delete40
PRE
AI
E
Engin Kirda *
N
Nenad Jovanović
C
Christopher Kruegel
G
Giovanni Vigna
DOI:10.1016/j.cose.2009.04.008delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Web applications are becoming the dominant way to provide access to online services. At the same time, web application vulnerabilities are being discovered and disclosed at an alarming rate. Web applications often make use of JavaScript code that is embedded into web pages to support dynamic client-side behavior. This script code is executed in the context of the user's web browser. To protect the user's environment from malicious JavaScript code, browsers use a sand-boxing mechanism that limits a script to access only resources associated with its origin site. Unfortunately, these security mechanisms fail if a user can be lured into downloading malicious JavaScript code from an intermediate, trusted site. In this case, the malicious script is granted full access to all resources (e.g., authentication tokens and cookies) that belong to the trusted site. Such attacks are called cross-site scripting (XSS) attacks. In general, XSS attacks are easy to execute, but difficult to detect and prevent. One reason is the high flexibility of HTML encoding schemes, offering the attacker many possibilities for circumventing server-side input filters that should prevent malicious scripts from being injected into trusted sites. Also, devising a client-side solution is not easy because of the difficulty of identifying JavaScript code as being malicious. This paper presents Noxes, which is, to the best of our knowledge, the first client-side solution to Mitigate cross-site scripting attacks. Noxes acts as a web proxy and uses both manual and automatically generated rules to mitigate possible cross-site scripting attempts. Noxes effectively protects against information leakage from the user's environment while requiring minimal user interaction and customization effort. (C) 2009 Elsevier Ltd. All rights reserved.
Keyword:
Cross-site scripting (XSS)
Web security
Intrusion detection
Client-side protection
Client-side defense
Firewall
Proxy
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

University of California System 封面图
University of California System
学者数:
37.5W
论文数: 33.7W
被引数: 6.6K
T
Technische Universitat Wien
学者数:
1.3W
论文数: 1.1W
被引数: 21
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
The problem of detrending when analysing potential indicators of disease elimination
err2019-11-01
err0
errOAAI
errAdjani Gama Dessavre; Emma Southall; Michael J. Tildesley; Louise Dyson
err分享
err收藏
Metallurgical Thermochemical Databases—A Review
err2013-07-18
err0
PREAI
errChristopher W. Bale; Gunnar Eriksson
err分享
err收藏