Home / Current Issue / Paper 1700555
Mitigating Cross Site Scripting Attacks With A Content Security Policy
Subject area: Science,Engineering and Technology · Area of research: Computer Engineering
Abstract
A content security policy (CSP) can help Web application developers and server administrators better control website content and avoid vulnerabilities to cross-site scripting (XSS). In experiments with a prototype website, the authors' CSP implementation successfully mitigated all XSS attack types in four popular browsers. An XSS attack involves injecting malicious script into a trusted website that executes on a visitor?s browser without the visitor?s knowledge and thereby enables the attacker to access sensitive user data, such as session tokens and cookies stored on the browser.1 With this data, attackers can execute several malicious acts, including identity theft, keylogging, phishing, user impersonation, and webcam activation.
Keywords
Content Security Policy, Cross Site Scripting, Web Applications, Input Sanitizers, Mitigating, Vulnerabilities.
References
[1] M. Johns, “Code Injection Vulnerabilities in Web Applications—Exemplified at Cross- Site Scripting,” PhD dissertation, Univ. of Passau, 2009; https://opus4.kobv.de/opus4-uni- passau/frontdoor/index/index /docId/144.
[2] Open Web Application Security Project, “OWASP Top 10 – 2013: The Ten Most Critical Web Application Security Risks,” 2013;www.owasp.org/index.php/Top10#OW ASP_Top_10_for_2013.
[3] I. Yusof and A.-S.K. Pathan, “Preventing Persistent Cross-Site Scripting (XSS) Attack by Applying Pattern Filtering Approach,” Proc. 5th IEEE Conf. Information and Communication Technology for the Muslim World (ICT4M14), 2014, pp. 1−6.
[4] L.K. Shar and H.B.K. Tan, “Defending against Cross-Site Scripting Attacks,” Computer, vol. 45, no. 3, 2012, pp. 55−62.
[5] E. Kirda et al., “Noxes: A Client-Side Solution for Mitigating Cross-Site Scripting Attacks,” Proc. 21st Ann.ACM Symp. Applied Computing (SAC06), 2006, pp. 330−337.
[6] T. Jim, N. Swamy, and M. Hicks, “Defeating Script Injection Attacks with Browser-Enforced Embedded Policies,” Proc. 16th Int’l ACM Conf. Worldwide Web (WWW07), 2007, pp. 601−610.
How to cite this paper
@article{1700555,
author = {R.Jyothi, Y.Bhavani, Sk.Mabibi, S.Priyanka, B. Sai Jyothi},
title = {Mitigating Cross Site Scripting Attacks With A Content Security Policy},
journal = {Iconic Research And Engineering Journals},
year = {2018},
volume = {1},
number = {10},
pages = {19-24},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1700555.pdf},
abstract = {A content security policy (CSP) can help Web application developers and server administrators better control website content and avoid vulnerabilities to cross-site scripting (XSS). In experiments with a prototype website, the authors' CSP implementation successfully mitigated all XSS attack types in four popular browsers. An XSS attack involves injecting malicious script into a trusted website that executes on a visitor?s browser without the visitor?s knowledge and thereby enables the attacker to access sensitive user data, such as session tokens and cookies stored on the browser.1 With this data, attackers can execute several malicious acts, including identity theft, keylogging, phishing, user impersonation, and webcam activation.
},
keywords = {Content Security Policy, Cross Site Scripting, Web Applications, Input Sanitizers, Mitigating, Vulnerabilities.
},
month = {April},
}