课题基金 / 基金详情

EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites

EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites
EAGER:在真实网站上实时执行内容安全策略
批准号:
1646662
负责人:
Yinzhi Cao
金额:
$9.47万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2017-08-31

项目摘要

项目成果

Yinzhi Cao的其他基金

相似基金

相关文献

中文摘要
翻译
跨站点脚本(XSS)漏洞——尽管已经被发现十多年了——仍然是最常见的web应用程序漏洞之一。在研究人员提出的所有防御措施中,一种被广泛采用的方法被称为内容安全策略(CSP)——它已被W3C标准化,并被所有主要的商业浏览器采用,如b谷歌Chrome、Internet Explorer、Safari和Firefox。虽然客户端采用CSP是成功的,但服务器端采用CSP是令人担忧的:根据最近对100万个网站的互联网规模调查,在研究时,前100名Alexa网站中只有2%启用了CSP,而90万个最不受欢迎的网站中只有0.00086%启用了CSP。这个项目创建了一种与后端语言无关的方法来帮助CSP在服务器端的部署,它可以自动转换现有的现实世界的web内容以符合CSP。该项目的关键观点是,尽管web脚本可能以不同的格式出现,包含实时的、与用户相关的信息,或者是动态生成的,但这些脚本都源自服务器并从特定模板生成。因此,项目可以根据脚本的相似性对它们进行分组,并推断脚本背后的模板。具体来说,有两种类型的脚本需要处理:内联脚本和动态脚本。对于前者,项目将脚本结构(例如For循环和if语句)以及每个对象的类型信息泛化为模板,并且只允许与模板匹配的脚本。对于后者,除了与模板匹配之外,项目还会在运行时实例化这些模板。
英文摘要
Cross-site scripting (XSS) vulnerabilities -- though being known for more than ten years -- are still one of the most commonly-found web application vulnerabilities in the wild. Among all the defenses proposed by researchers, one widely-adopted approach is called Content Security Policy (CSP) -- which has been standardized by W3C and adopted by all major commercial browsers, such as Google Chrome, Internet Explorer, Safari, and Firefox. Though being successful in the client-side adoption, the server-side adoption of CSP is worrisome: According to a recent Internet-scale survey of 1M websites, at the time of the study, only 2% of top 100 Alexa websites enabled CSP, and 0.00086% of 900,000 least popular sites did so. This project is creating a backend-language-agnostic approach to help CSP's deployment at the server side, which automatically transforms existing real-world web contents to comply with CSP. The key insight of the project is that although web scripts may occur in different formats, contain real-time, user-related information, or be generated dynamically, these scripts are originated from the server and generated from certain templates. Therefore, the project can group scripts based on their similarities and infer the templates behind the scripts. Specifically, there are two types of scripts to handle: inline scripts and dynamic scripts. For the former, the project generalizes the script structures -- such as for loop and if statement -- as well as the type information of each object as templates and only allows scripts that matches the templates. For the latter, in addition to the matching with templates, the project instantiates these templates in runtime.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: TCR: Transitioning Differentially Private Federated Learning to Enable Collaborative, Intelligent, Fair Skin Disease Diagnostics on Medical Imaging Cyberinfrastructure
  • 批准号:
    2319742
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2024
  • 负责人:
    Yinzhi Cao
  • 依托单位:
Collaborative Research: DASS: Assessing the Relationship Between Privacy Regulations and Software Development to Improve Rulemaking and Compliance
  • 批准号:
    2317185
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2023
  • 负责人:
    Yinzhi Cao
  • 依托单位:
SaTC: CORE: Small: Studying and Measuring the Consequence of Prototype Pollution Vulnerabilities Automatically via Joint Taintflow Analysis
  • 批准号:
    2154404
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Yinzhi Cao
  • 依托单位:
CAREER: Mining and Exploiting Web Vulnerabilities of Prototype-based Programming Languages via Object Property Graph
  • 批准号:
    2046361
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $56.05万
  • 财政年份:
    2021
  • 负责人:
    Yinzhi Cao
  • 依托单位:
国内基金
海外基金
Immuno-Real Time PCR法精确定量血清MG7抗原及在早期胃癌预警中的价值
无色ReAl3(BO3)4(Re=Y,Lu)系列晶体紫外倍频性能与器件研究