Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site Scripting

Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site Scripting
复制标题

DOI:
10.14722/ndss.2018.23309
复制
发表时间:
2018
期刊:
Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
William Melicher;Anupam Das;Mahmood Sharif;Lujo Bauer;Limin Jia
William Melicher;Anupam Das;Mahmood Sharif;Lujo Bauer;Limin Jia
中科院分区:
其他
文献类型:
--
作者:
William Melicher;Anupam Das;Mahmood Sharif;Lujo Bauer;Limin Jia

文献摘要

被引文献

相似文献

跨站脚本(XSS)漏洞是最常被报告的Web应用程序漏洞。随着复杂的JavaScript应用程序变得更加广泛,DOM(文档对象模型)XSS漏洞——一种漏洞位于客户端JavaScript而非服务器端代码的XSS漏洞类型——正变得越来越常见。作为这项工作的第一个贡献,我们使用在JavaScript引擎中嵌入污点跟踪的浏览器,凭经验评估DOM XSS对网络的影响。基于先前一项对热门网站进行爬取的研究中所使用的方法,我们收集了一个潜在DOM XSS漏洞的当前数据集。我们改进了确认XSS漏洞的方法,并且使用这种改进的方法,我们发现的漏洞比应用于同一数据集的先前方法多出83%。作为第二个贡献,我们确定了DOM XSS漏洞的成因并讨论了如何预防它们。我们的一个发现示例是,自定义HTML模板设计——一种类似于参数化SQL可预防DOM XSS漏洞的设计模式——在实践中可能存在缺陷,从而允许DOM XSS攻击。作为我们的第三个贡献,我们使用实际示例评估了三种静态分析工具检测通过动态分析技术发现的DOM XSS漏洞的错误率。我们发现静态分析工具遗漏了我们动态分析所发现的90%的漏洞,尽管一些工具的误报率可能非常低,同时还能发现动态分析未发现的漏洞。
—Cross-site scripting (XSS) vulnerabilities are the most frequently reported web application vulnerability. As complex JavaScript applications become more widespread, DOM (Document Object Model) XSS vulnerabilities—a type of XSS vulnerability where the vulnerability is located in client-side JavaScript, rather than server-side code—are becoming more common. As the first contribution of this work, we empirically assess the impact of DOM XSS on the web using a browser with taint tracking embedded in the JavaScript engine. Building on the methodology used in a previous study that crawled popular websites, we collect a current dataset of potential DOM XSS vulnerabilities. We improve on the methodology for confirming XSS vulnerabilities, and using this improved methodology, we find 83% more vulnerabilities than previous methodology applied to the same dataset. As a second contribution, we identify the causes of and discuss how to prevent DOM XSS vulnerabilities. One example of our findings is that custom HTML templating designs—a design pattern that could prevent DOM XSS vulnerabilities analogous to parameterized SQL—can be buggy in practice, allowing DOM XSS attacks. As our third contribution, we evaluate the error rates of three static-analysis tools to detect DOM XSS vulnerabilities found with dynamic analysis techniques using in-the-wild examples. We find static-analysis tools to miss 90% of bugs found by our dynamic analysis, though some tools can have very few false positives and at the same time find vulnerabilities not found using the dynamic analysis.