Security Implications of Using Third-Party Resources in the World Wide Web

Security Implications of Using Third-Party Resources in the World Wide Web
复制标题

在万维网上使用第三方资源的安全影响

DOI:
10.1109/aieee.2018.8592057
复制
发表时间:
2018
期刊:
2018 IEEE 6th Workshop on Advances in Information, Electronic and Electrical Engineering (AIEEE)
影响因子:
--
通讯作者:
Arturs Lavrenovs
Arturs Lavrenovs
中科院分区:
--
文献类型:
--
作者:
Karlis Podins;Arturs Lavrenovs

文献摘要

被引文献

相似文献

现代网页与来自“页面”一词的静态内涵没有任何共同之处-它是由活动内容创建并在浏览器中执行的动态独特体验,由托管在许多不同域的各种资源即时组装而成。活动内容增加了攻击面,自然使用户面临许多新的威胁。一个流行的安全建议是部署主动内容拦截器插件,如NoScript,不幸的是,它们无法有效地阻止攻击。内容安全策略(CSP)可以有效地抵御这些攻击,但我们展示了网站管理员或外部资源托管商做出的糟糕决策如何使CSP无效。作为一个实际的贡献,我们已经扫描了Alexa Top Million网页的不安全CSP配置,并在一年后进行了跟踪扫描以观察变化。最初,只有2%的网页被观察到使用CSP,但在后续的百分比增加了一倍多。我们发现大量网页的CSP规则过于宽松,大约5%的网站有CSP仍然允许攻击者在商业外部资源上托管恶意内容,同时在利用跨站点脚本漏洞时满足CSP规则。我们还提供了一个模型的问题域,形式化的用户和域模型,以及首选的用户安全策略。
Modern web pages have nothing in common with the static connotation coming from the word “page” - it is a dynamic unique experience created by active content and executed within browser, just-in-time assembled from various resources hosted on many different domains. Active content increases attack surface naturally exposing users to many novel threats. A popular security advice has been to deploy active content blocker plugins like NoScript, unfortunately they are not capable to effectively stop the attacks. Content Security Policy (CSP) can be effective against these attacks, but we demonstrate how poor decisions made by website administrators or external resource hosters can render CSP ineffective. As a practical contribution, we have scanned Alexa Top Million web pages for insecure CSP configuration and conducted a follow up scan one year later to observe the changes. Initially only 2% of those web pages were observed to use CSP but in the follow-up the percentage more than doubled. We have found a substantial number of web pages with too loose CSP rules, about 5% of websites that have CSP still enable determined attacker to host malicious content on commercial external resources while fulfilling the CSP rule when exploiting Cross-Site Scripting vulnerability. We also provide a model for the problem domain, formalization of user and domain models, and preferred user security policy.