The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Introduction Crisis management is a critical organizational function. Failure can result in serious harm to stakeholders, losses for an orga...
-
Publication date: 1 July 2017 Source: Cancer Letters, Volume 397 Author(s): Makoto Sano, Yoshimi Ichimaru, Masahiro Kurita, Emiko Hayashi,...
-
Maritime Logistics • General Ship Knowledge • Seaborne Cargoes and Dangerous Goods • Cargo Planning • Marine Terminal Operations • Modal and...
-
136 Unit 6 • Cause-Effect Essays What is a great topic for a cause-effect essay? This type of essay may focus more on the causes or more on ...
-
Winners of the 13th Annual 2017 Info Security PG's Global Excellence Awards® from #AlexandrosSfakianakis via Alexandros G.Sfakianakis ...
-
918 quotes have been tagged as self-confidence: Edgar Allan Poe: ‘I have great faith in fools - self-confidence my friends will call it.’, R...
-
Apply to 39 Fifth Third Bank Personal Banker jobs in United States on LinkedIn. Sign-up today, leverage your professional network, and get h...
-
Publication date: Available online 7 April 2017 Source: Experimental Cell Research Author(s): Guoxing Li, Huiyang Song, Weihua Yang, Shans...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου