JSSignature: eliminating third-party-hosted JavaScript infection threats using digital signatures
JSSignature: eliminating third-party-hosted JavaScript infection threats using digital signatures
复制标题
JSSignature:使用数字签名消除第三方托管的 JavaScript 感染威胁
作者:
Kousha Nakhaei;Fateme Ansari;Ebrahim Ansari
Today, third-party JavaScript resources are an indispensable part of the web platform. More than 88% of the world’s top websites include at least one JavaScript resource from a remote host. However, there is a great security risk behind using a third-party JavaScript resource, if an attacker can infect one of these remote JavaScript resources all websites those have included the script would be at risk. In this paper, we present JSSignature, an entirely at the client-side pure JavaScript framework in order to validate third-party JavaScript resources using a digital signature. Therefore, all included JavaScript resources are checked against the integrity, authentication and non-repudiation risks before the execution. In contrary to existing methods, JSSignature protects web pages regardless of third-party resource infection nature while it does not set any restrictions on trusted JavaScript providers. This approach has an acceptable one-time performance overhead and is an easily deployable add-in. We have validated the proposed solution by applying tests on an implemented version (https://iasbs.ac.ir/~ansari/jssignature/demo.html). A pre-published version of this paper is available at arXiv website (https://arxiv.org/pdf/1812.03939.pdf).
DOI:
10.1109/csf.2009.11
发表时间:
2009
期刊:
--
影响因子:
--
作者:
Maffeis S
通讯作者:
Maffeis S