The More Things Change, the More They Stay the Same: Integrity of Modern JavaScript

The More Things Change, the More They Stay the Same: Integrity of Modern JavaScript
复制标题

事物变化越多,它们就越保持不变:现代 JavaScript 的完整性

DOI:
10.1145/3543507.3583395
复制
发表时间:
2023
期刊:
Proceedings of the ACM Web Conference (WWW
影响因子:
--
通讯作者:
Nikiforakis, Nick
Nikiforakis, Nick
中科院分区:
--
文献类型:
--
作者:
So, Johnny;Ferdman, Michael;Nikiforakis, Nick

文献摘要

参考文献

被引文献

相似文献

现代网络是远程资源的集合,这些资源通过它们的位置来识别,并由相互交织的信任网络组成。供应链攻击通过利用其通常大量的提供资源(例如JavaScript)的可信第三方来危害目标域的用户。JavaScript的普遍性,加上它在客户端机器上执行任意代码的能力,使这种特殊的Web资源成为供应链攻击的理想载体。目前,还没有一个强大的方法来让用户浏览网页,以验证他们从第三方收到的脚本内容是预期的content.In本文中,我们提出了关键的见解,通知鲁棒的完整性机制的设计,来自我们的大规模分析,我们收集的6M脚本,同时每天抓取44K域77天。我们发现,在现代网络生态系统中,经常变化的脚本应该被视为一等公民,并且脚本变化的方式随着时间的推移保持不变。此外,我们还分析了使用严格的完整性验证(例如,子资源完整性),提供了一个更完整的视角,并证明仅使用严格的完整性不能提供令人满意的安全保证。我们的结论是,这是不可行的客户端区分良性的变化,恶意的没有额外的,外部的知识,激励需要一个新的协议,为客户端提供必要的上下文来评估脚本变化的潜在后果。
The modern web is a collection of remote resources that are identified by their location and composed of interleaving networks of trust. Supply chain attacks compromise the users of a target domain by leveraging its often large set of trusted third parties who provide resources such as JavaScript. The ubiquity of JavaScript, paired with its ability to execute arbitrary code on client machines, makes this particular web resource an ideal vector for supply chain attacks. Currently, there exists no robust method for users browsing the web to verify that the script content they receive from a third party is the expected content.In this paper, we present key insights to inform the design of robust integrity mechanisms, derived from our large-scale analyses of the 6M scripts we collected while crawling 44K domains every day for 77 days. We find that scripts that frequently change should be considered first-class citizens in the modern web ecosystem, and that the ways in which scripts change remain constant over time. Furthermore, we present analyses on the use of strict integrity verification (e.g., Subresource Integrity) at the granularity of the script providers themselves, offering a more complete perspective and demonstrating that the use of strict integrity alone cannot provide satisfactory security guarantees. We conclude that it is infeasible for a client to distinguish benign changes from malicious ones without additional, external knowledge, motivating the need for a new protocol to provide clients the necessary context to assess the potential ramifications of script changes.
DOI: 10.1145/3038912.3052686
发表时间: 2017-04
期刊: Proceedings of the 26th International Conference on World Wide Web
影响因子: --
作者:
Deepak Kumar;Zane Ma;Zakir Durumeric;Ariana Mirian;Joshua Mason;J. A. Halderman;Michael Bailey
通讯作者: Deepak Kumar;Zane Ma;Zakir Durumeric;Ariana Mirian;Joshua Mason;J. A. Halderman;Michael Bailey
DOI: --
发表时间: 2020
期刊: The Web Conference
影响因子: --
作者:
B. Chapuis;O. Omolola;M. Cherubini;Mathias Humbert;Kévin Huguenin
通讯作者: Kévin Huguenin
JSSignature:使用数字签名消除第三方托管的 JavaScript 感染威胁
DOI: --
发表时间: 2018
影响因子: 2.6
作者:
Kousha Nakhaei;Fateme Ansari;Ebrahim Ansari
通讯作者: Ebrahim Ansari
如何训练你的浏览器
DOI: --
发表时间: 2016
影响因子: 2.3
作者:
Dimitris Mitropoulos;Konstantinos Stroggylos;D. Spinellis;A. Keromytis
通讯作者: A. Keromytis
DOI: --
发表时间: 2018
期刊: Int. J. Secur. Networks
影响因子: --
作者:
Ronak Shah;Kailas Patil
通讯作者: Kailas Patil