首页> 外文OA文献 >Content Security Problems?
【2h】

Content Security Problems?

机译:内容安全问题?:评估内容安全策略的有效性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Content Security Policy (CSP) is an emerging W3C standard introduced to mitigate the impact of content injection vulnerabilities on websites. We perform a systematic, largescale analysis of four key aspects that impact on the effectiveness of CSP: browser support, website adoption, correct configuration and constant maintenance. While browser support is largely satisfactory, with the exception of few notable issues, our analysis unveils several shortcomings relative to the other three aspects. CSP appears to have a rather limited deployment as yet and, more crucially, existing policies exhibit a number of weaknesses and misconfiguration errors. Moreover, content security policies are not regularly updated to ban insecure practices and remove unintended security violations. We argue that many of these problems can be fixed by better exploiting the monitoring facilities of CSP, while other issues deserve additional research, being more rooted into the CSP design.
机译:内容安全策略(CSP)是一个新兴的W3C标准,以减轻内容注入漏洞对网站的影响。我们对四个关键方面进行系统,大型分析,这对CSP的有效性产生了影响:浏览器支持,网站采用,正确配置和持续维护。虽然浏览器支持在很大程度上是令人满意的,但除了几个显着的问题外,我们的分析揭示了相对于其他三个方面的几个缺点。 CSP似乎有一个相当有限的部署,尚未且令人遗憾的是,现有的策略表现出许多弱点和错误配置错误。此外,内容安全策略不定期更新为禁止不安全的实践并删除意外的安全违规。我们认为,通过更好地利用CSP的监测设施,可以解决许多这些问题,而其他问题则应得到额外的研究,更加植根于CSP设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号