Visible to the public Adopting Strict Content Security Policy for XSS Protection

TitleAdopting Strict Content Security Policy for XSS Protection
Publication TypeConference Paper
Year of Publication2016
AuthorsWeichselbaum, L., Spagnuolo, M., Janc, A.
Conference Name2016 IEEE Cybersecurity Development (SecDev)
Date Publishednov
ISBN Number978-1-5090-5589-0
KeywordsCollaboration, computer security, Conferences, content security policy, content-injection flaw, CSP, data protection, Google, governance, Government, Internet, Licenses, policy, policy-based governance, Production, pubcrawl, script source, security of data, security policies, Tutorials, Web application flaw, XSS protection
Abstract

Content Security Policy is a mechanism designed to prevent the exploitation of XSS - the most common high-risk web application flaw. CSP restricts which scripts can be executed by allowing developers to define valid script sources; an attacker with a content-injection flaw should not be able to force the browser to execute arbitrary malicious scripts. Currently, CSP is commonly used in conjunction with domain-based script whitelist, where the existence of a single unsafe endpoint in the script whitelist effectively removes the value of the policy as a protection against XSS ( some examples ).

URLhttps://ieeexplore.ieee.org/document/7839808/
DOI10.1109/SecDev.2016.039
Citation Keyweichselbaum_adopting_2016