How to Train Your Browser

How to Train Your Browser
复制标题

如何训练你的浏览器

DOI:
--
复制
发表时间:
2016
影响因子:
2.3
通讯作者:
A. Keromytis
A. Keromytis
中科院分区:
计算机科学4区
文献类型:
--
作者:
Dimitris Mitropoulos;Konstantinos Stroggylos;D. Spinellis;A. Keromytis

文献摘要

被引文献

相似文献

跨站脚本(XSS)是最常见的Web应用程序漏洞之一。因此,它有时被称为“Web缓冲区溢出”。从防止未经授权的本机代码执行(代码注入的典型目标)的实践的当前状态绘制平行,我们提出了一个脚本白名单的方法来驯服JavaScript驱动的XSS攻击。我们的方案涉及到一个透明的脚本拦截层放置在浏览器的JavaScript引擎。该层旨在检测从每个可能的路由到达浏览器的每个脚本,并将其与正在访问的站点或页面的有效脚本列表进行比较;列表中未列出的脚本将被阻止执行。为了避免由微小的语法变化(例如,由于动态代码生成),我们的层在比较脚本时使用上下文指纹的概念。上下文指纹是表示脚本及其执行上下文的特定元素的标识符。指纹可以很容易地丰富新的元素,如果需要的话,以提高所提出的方法的鲁棒性。该列表可以由网站的管理员或受信任的第三方填充。为了验证我们的方法,我们开发了一个原型,并成功地测试了它对50多个现实世界中易受攻击的Web应用程序进行的广泛攻击。我们在8个大量使用JavaScript的网站上测量了建议解决方案的浏览性能开销。我们的机制强加了11.1%的平均开销上的执行时间的JavaScript引擎。当作为完整浏览会话的一部分进行测量时,对于所有测试的网站,我们的层引入的开销小于0.05%。当脚本元素被更改或在服务器端添加新脚本时,需要一个新的指纹生成阶段。为了研究上下文指纹的时间方面,我们基于相同的网站进行了短期和长期实验。前者显示,在短时间内(10天),八个网站中有七个的大部分有效指纹保持不变(平均超过92%)。然而,后者表明,从长远来看,不改变的指纹数量会减少。这两个实验都可以被视为研究网络白名单方法可行性的首批尝试之一。
Cross-Site Scripting (XSS) is one of the most common web application vulnerabilities. It is therefore sometimes referred to as the “buffer overflow of the web.” Drawing a parallel from the current state of practice in preventing unauthorized native code execution (the typical goal in a code injection), we propose a script whitelisting approach to tame JavaScript-driven XSS attacks. Our scheme involves a transparent script interception layer placed in the browser’s JavaScript engine. This layer is designed to detect every script that reaches the browser, from every possible route, and compare it to a list of valid scripts for the site or page being accessed; scripts not on the list are prevented from executing. To avoid the false positives caused by minor syntactic changes (e.g., due to dynamic code generation), our layer uses the concept of contextual fingerprints when comparing scripts. Contextual fingerprints are identifiers that represent specific elements of a script and its execution context. Fingerprints can be easily enriched with new elements, if needed, to enhance the proposed method’s robustness. The list can be populated by the website’s administrators or a trusted third party. To verify our approach, we have developed a prototype and tested it successfully against an extensive array of attacks that were performed on more than 50 real-world vulnerable web applications. We measured the browsing performance overhead of the proposed solution on eight websites that make heavy use of JavaScript. Our mechanism imposed an average overhead of 11.1% on the execution time of the JavaScript engine. When measured as part of a full browsing session, and for all tested websites, the overhead introduced by our layer was less than 0.05%. When script elements are altered or new scripts are added on the server side, a new fingerprint generation phase is required. To examine the temporal aspect of contextual fingerprints, we performed a short-term and a long-term experiment based on the same websites. The former, showed that in a short period of time (10 days), for seven of eight websites, the majority of valid fingerprints stay the same (more than 92% on average). The latter, though, indicated that, in the long run, the number of fingerprints that do not change is reduced. Both experiments can be seen as one of the first attempts to study the feasibility of a whitelisting approach for the web.