CISPA
Browse
cispa_all_2894.pdf (791.58 kB)

ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices

Download (791.58 kB)
conference contribution
posted on 2023-11-29, 18:10 authored by Marius Musch, Marius Steffens, Sebastian Roth, Ben StockBen Stock, Martin Johns
The direct client-side inclusion of cross-origin JavaScript resources in Web applications is a pervasive practice to consume third-party services and to utilize externally provided libraries. The downside of this practice is that such external code runs in the same context and with the same privileges as the first-party code. Thus, all potential security problems in the code directly affect the including site. To explore this problem, we present an empirical study which shows that more than 25% of all sites affected by Client-Side Cross-Site Scripting are only vulnerable due to a flaw in the included third-party code. Motivated by this finding, we propose ScriptProtect, a non-intrusive transparent protective measure to address security issues introduced by external script resources. ScriptProtect automatically strips third-party code from the ability to conduct unsafe string-to-code conversions. Thus, it effectively removes the root-cause of Client-Side XSS without affecting first-party code in this respective. As ScriptProtect is realized through a lightweight JavaScript instrumentation, it does not require changes to the browser and only incurs a low runtime overhead of about 6%. We tested its compatibility on the Alexa Top 5,000 and found that 30% of these sites could benefit from ScriptProtect’s protection today without changes to their application code.

History

Preferred Citation

Marius Musch, Marius Steffens, Sebastian Roth, Ben Stock and Martin Johns. ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices. In: ACM ASIA Conference on Computer and Communications Security (AsiaCCS). 2019.

Primary Research Area

  • Threat Detection and Defenses

Secondary Research Area

  • Empirical and Behavioral Security

Name of Conference

ACM ASIA Conference on Computer and Communications Security (AsiaCCS)

Legacy Posted Date

2019-05-23

Open Access Type

  • Unknown

BibTeX

@inproceedings{cispa_all_2894, title = "ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices", author = "Musch, Marius and Steffens, Marius and Roth, Sebastian and Stock, Ben and Johns, Martin", booktitle="{ACM ASIA Conference on Computer and Communications Security (AsiaCCS)}", year="2019", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC