JSSignature: eliminating third-party-hosted JavaScript infection threats using digital signatures

JSSignature: eliminating third-party-hosted JavaScript infection threats using digital signatures
复制标题

JSSignature:使用数字签名消除第三方托管的 JavaScript 感染威胁

DOI:
--
复制
发表时间:
2018
影响因子:
2.6
通讯作者:
Ebrahim Ansari
Ebrahim Ansari
中科院分区:
--
文献类型:
--
作者:
Kousha Nakhaei;Fateme Ansari;Ebrahim Ansari

文献摘要

参考文献

被引文献

相似文献

今天,第三方JavaScript资源是Web平台不可或缺的一部分。超过88%的世界顶级网站包含至少一个来自远程主机的JavaScript资源。然而,使用第三方JavaScript资源背后存在很大的安全风险,如果攻击者可以感染这些远程JavaScript资源之一,则包含该脚本的所有网站都将面临风险。在本文中,我们提出了JSSignature,一个完全在客户端的纯JavaScript框架,以验证第三方JavaScript资源使用数字签名。因此,在执行之前,会针对完整性、身份验证和不可否认风险检查所有包含的JavaScript资源。与现有方法相反,JSSignature保护网页,而不管第三方资源感染的性质,同时它不对可信的JavaScript提供商设置任何限制。这种方法具有可接受的一次性性能开销,并且是一种易于部署的加载项。我们已经通过在一个已实现的版本(https://iasbs.ac.ir/jssignature/demo.html)上应用测试来验证了所提出的解决方案。这篇论文的预发表版本可在arXiv网站(https://arxiv.org/pdf/1812.03939.pdf)上查阅。
Today, third-party JavaScript resources are an indispensable part of the web platform. More than 88% of the world’s top websites include at least one JavaScript resource from a remote host. However, there is a great security risk behind using a third-party JavaScript resource, if an attacker can infect one of these remote JavaScript resources all websites those have included the script would be at risk. In this paper, we present JSSignature, an entirely at the client-side pure JavaScript framework in order to validate third-party JavaScript resources using a digital signature. Therefore, all included JavaScript resources are checked against the integrity, authentication and non-repudiation risks before the execution. In contrary to existing methods, JSSignature protects web pages regardless of third-party resource infection nature while it does not set any restrictions on trusted JavaScript providers. This approach has an acceptable one-time performance overhead and is an easily deployable add-in. We have validated the proposed solution by applying tests on an implemented version (https://iasbs.ac.ir/~ansari/jssignature/demo.html). A pre-published version of this paper is available at arXiv website (https://arxiv.org/pdf/1812.03939.pdf).
基于语言的不可信 JavaScript 隔离
DOI: 10.1109/csf.2009.11
发表时间: 2009
期刊: --
影响因子: --
作者:
Maffeis S
通讯作者: Maffeis S