An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources

An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources
复制标题

Web子资源完整性验证机制使用的实证研究

DOI:
--
复制
发表时间:
2020
期刊:
The Web Conference
影响因子:
--
通讯作者:
Kévin Huguenin
Kévin Huguenin
中科院分区:
--
文献类型:
--
作者:
B. Chapuis;O. Omolola;M. Cherubini;Mathias Humbert;Kévin Huguenin

文献摘要

参考文献

被引文献

相似文献

Web开发人员可以(并且确实)在他们的网页中包含子资源,如脚本,样式表和图像。这样的子资源可以存储在内容分发网络(CDN)上。如果子资源被破坏,这种做法会带来安全和隐私风险。子资源完整性(SRI)建议,由W3C在2016年年中发布,允许开发人员在其网页中包含子资源,以便Web浏览器在加载子资源之前验证其完整性。在本文中,我们进行了第一次大规模的纵向研究,使用SRI在Web上通过分析大量的抓取(103B URL)的Web在过去的3.5年。我们的研究结果表明,SRI的采用是适度的(10%),但增长速度越来越快,并且受到流行的库开发人员的实践(例如,Bootstrap)和CDN运营商(例如,jsDelivr)。我们通过对Web开发人员的调查(N=)补充了我们对SRI的分析:它表明相当大比例的开发人员知道SRI并了解其基本功能,但他们中的大多数人忽略了建议的重要方面。调查结果还表明,开发人员对SRI的集成大多是手动的,因此不具有可扩展性,并且容易出错。这就要求在构建工具中更好地集成SRI。
Web developers can (and do) include subresources such as scripts, stylesheets and images in their webpages. Such subresources might be stored on content delivery networks (CDNs). This practice creates security and privacy risks, should a subresource be corrupted. The subresource integrity (SRI) recommendation, released in mid-2016 by the W3C, enables developers to include digests in their webpages in order for web browsers to verify the integrity of subresources before loading them. In this paper, we conduct the first large-scale longitudinal study of the use of SRI on the Web by analyzing massive crawls (≈ 3B URLs) of the Web over the last 3.5 years. Our results show that the adoption of SRI is modest (≈), but grows at an increasing rate and is highly influenced by the practices of popular library developers (e.g., Bootstrap) and CDN operators (e.g., jsDelivr). We complement our analysis about SRI with a survey of web developers (N=): It shows that a substantial proportion of developers know SRI and understand its basic functioning, but most of them ignore important aspects of the recommendation. The results of the survey also show that the integration of SRI by developers is mostly manual – hence not scalable and error prone. This calls for a better integration of SRI in build tools.
阅读本文可能会损害您的计算机:恶意软件警告的心理学
DOI: 10.1016/j.chb.2014.09.014
发表时间: 2014
影响因子: 9.9
作者:
Modic D
通讯作者: Modic D