2014
DOI: 10.1007/978-3-319-11379-1_11
|View full text |Cite
|
Sign up to set email alerts
|

Why Is CSP Failing? Trends and Challenges in CSP Adoption

Abstract: Abstract. Content Security Policy (CSP) has been proposed as a principled and robust browser security mechanism against content injection attacks such as XSS. When configured correctly, CSP renders malicious code injection and data exfiltration exceedingly difficult for attackers. However, despite the promise of these security benefits and being implemented in almost all major browsers, CSP adoption is minuscule-our measurements show that CSP is deployed in enforcement mode on only 1% of the Alexa Top 100. In … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

5
75
0

Year Published

2015
2015
2019
2019

Publication Types

Select...
4
3

Relationship

0
7

Authors

Journals

citations
Cited by 56 publications
(80 citation statements)
references
References 9 publications
5
75
0
Order By: Relevance
“…There are many important differences between the present paper and this previous work [23,35]. First, the focus of the works is quite different, since we are only interested in assessing the trends and the effectiveness of the current CSP adoption, while [23,35] put great emphasis on semi-automated policy generation.…”
Section: Csp Deploymentmentioning
confidence: 95%
See 3 more Smart Citations
“…There are many important differences between the present paper and this previous work [23,35]. First, the focus of the works is quite different, since we are only interested in assessing the trends and the effectiveness of the current CSP adoption, while [23,35] put great emphasis on semi-automated policy generation.…”
Section: Csp Deploymentmentioning
confidence: 95%
“…It is interesting to observe that an earlier study [35] conducted in March 2014 identified only 850 websites using CSP in the Alexa Top 1M, hence the CSP adoption has significantly expanded in the last two years, approximately of a ten factor. An inspection of our dataset shows that a number of popular hosting services have deployed CSP nowadays, including Blogger, Tumblr and Shopify among others.…”
Section: Current Adoption Of Cspmentioning
confidence: 99%
See 2 more Smart Citations
“…This makes the endorsement mechanism compatible with both CSP 1.0 and CSP 2.0. Weissbacher et al [39] measure a low deployment rate of CSP and conduct studies to analyze the practical challenges for deploying CSP policies. They point out that it is di cult to define a policy for a web page that utilizes the full potential of CSP.…”
Section: Resultsmentioning
confidence: 99%