课题基金 / 基金详情

EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites

EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites
EAGER:在真实网站上实时执行内容安全策略
批准号:
1646662
负责人:
Yinzhi Cao
金额:
$9.47万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2017-08-31

项目摘要

项目成果

Yinzhi Cao的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Cross-site scripting (XSS) vulnerabilities -- though being known for more than ten years -- are still one of the most commonly-found web application vulnerabilities in the wild. Among all the defenses proposed by researchers, one widely-adopted approach is called Content Security Policy (CSP) -- which has been standardized by W3C and adopted by all major commercial browsers, such as Google Chrome, Internet Explorer, Safari, and Firefox. Though being successful in the client-side adoption, the server-side adoption of CSP is worrisome: According to a recent Internet-scale survey of 1M websites, at the time of the study, only 2% of top 100 Alexa websites enabled CSP, and 0.00086% of 900,000 least popular sites did so. This project is creating a backend-language-agnostic approach to help CSP's deployment at the server side, which automatically transforms existing real-world web contents to comply with CSP. The key insight of the project is that although web scripts may occur in different formats, contain real-time, user-related information, or be generated dynamically, these scripts are originated from the server and generated from certain templates. Therefore, the project can group scripts based on their similarities and infer the templates behind the scripts. Specifically, there are two types of scripts to handle: inline scripts and dynamic scripts. For the former, the project generalizes the script structures -- such as for loop and if statement -- as well as the type information of each object as templates and only allows scripts that matches the templates. For the latter, in addition to the matching with templates, the project instantiates these templates in runtime.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: TCR: Transitioning Differentially Private Federated Learning to Enable Collaborative, Intelligent, Fair Skin Disease Diagnostics on Medical Imaging Cyberinfrastructure
  • 批准号:
    2319742
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2024
  • 负责人:
    Yinzhi Cao
  • 依托单位:
Collaborative Research: DASS: Assessing the Relationship Between Privacy Regulations and Software Development to Improve Rulemaking and Compliance
  • 批准号:
    2317185
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2023
  • 负责人:
    Yinzhi Cao
  • 依托单位:
SaTC: CORE: Small: Studying and Measuring the Consequence of Prototype Pollution Vulnerabilities Automatically via Joint Taintflow Analysis
  • 批准号:
    2154404
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Yinzhi Cao
  • 依托单位:
CAREER: Mining and Exploiting Web Vulnerabilities of Prototype-based Programming Languages via Object Property Graph
  • 批准号:
    2046361
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $56.05万
  • 财政年份:
    2021
  • 负责人:
    Yinzhi Cao
  • 依托单位:
国内基金
海外基金
Immuno-Real Time PCR法精确定量血清MG7抗原及在早期胃癌预警中的价值
无色ReAl3(BO3)4(Re=Y,Lu)系列晶体紫外倍频性能与器件研究