The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
The population of American Indians and Alaska Natives (AIAN) in the USA, which comprise about 5 million individuals, have worse health outco...
-
Abstract Purpose C-reactive protein and procalcitonin are reliable early predictors of infection after colorectal surgery. However, the ...
-
. The copytext for the following essays is the 1777 edition of the Essays and Treatises on Several Subjects. The essays themselves all appea...
-
[prev in list] [next in list] [prev in thread] [next in thread] List: enlightenment-svn Subject: E SVN: raster trunk/illume/dicts From: Enli...
-
Strangers on the Mountain They had lived in the woodlands, twenty-five miles from New York City, for generations. Why were people so afraid ...
-
Famous Quotes: Hand Picked Funny, Inspirational and Love Quotes. Looking for the best famous quotes? from #AlexandrosSfakianakis via Alexa...
-
SMARTCOCKPIT; Our #1 goal, since 2000, is to offer the most extensive online aviation resource to worldwide professional pilots. We desire t...
-
Abstract Monitoring blood loss is important for management of surgical patients. This study reviews a device (Triton) that uses computer a...
-
<span class="paragraphSection"><div class="boxTitle">Abstract</div>Despite many advances in the study ...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου