2016
DOI: 10.1002/sec.1562
|View full text |Cite
|
Sign up to set email alerts
|

A systematic study of content security policy in web applications

Abstract: Content Security Policy (CSP) is a popular and effective security mechanism against content injection vulnerabilities such as cross‐site scripting for web applications. Unfortunately, there are many problems in analysis, design, and evaluation of CSP, which are hindering the wide adoption of CSP by real‐world web applications. In this paper, we give a systematic study and propose workable solutions for these problems. We systemically analyze the methodology of CSP, namely how it works and prevents attacks. We … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
3

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(1 citation statement)
references
References 12 publications
0
1
0
Order By: Relevance
“…In concurrent independent work, Liu et al [16] formalized a core of the CSP 1.0 semantics. The authors used the semantics to reason on policy permissiveness and to design algorithms for removing redundant information from content security policies.…”
Section: Csp Semanticsmentioning
confidence: 99%
“…In concurrent independent work, Liu et al [16] formalized a core of the CSP 1.0 semantics. The authors used the semantics to reason on policy permissiveness and to design algorithms for removing redundant information from content security policies.…”
Section: Csp Semanticsmentioning
confidence: 99%