A Case-Control Study on the Server-Side Bandages Against XSS

dc.contributor.authorRuohonen J.
dc.contributor.authorLeppänen V.
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id36035085
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/36035085
dc.date.accessioned2022-10-28T13:49:30Z
dc.date.available2022-10-28T13:49:30Z
dc.description.abstract<p>This paper surveys the server-side use of security-related options for protecting websites against cross-site scripting (XSS) attacks. By using data from a bug bounty platform, the use of these header-based options is approached with a case-control study that contrasts popular Internet domains against less popular domains that have explicitly been veried to have been vulnerable to XSS. According to the results based on the analysis of nearly 800 thousand domains, (a) the header-based security options are only infrequently used. However, (b) the domains known to have been vulnerable to XSS have been much less likely to use these options compared to popular domains. Furthermore, (c) the options surveyed tend to statistically form clear latent dimensions, which can be speculated to relate to the eort required to enforce strict security policies for websites.</p><p></p><p><br /></p>
dc.identifier.isbn978-86-7031-473-3
dc.identifier.issn1613-0073
dc.identifier.jour-issn1613-0073
dc.identifier.olddbid184567
dc.identifier.oldhandle10024/167661
dc.identifier.urihttps://www.utupub.fi/handle/11111/37849
dc.identifier.urlhttp://ceur-ws.org/Vol-2217/paper-ruo.pdf
dc.identifier.urnURN:NBN:fi-fe2021042719874
dc.language.isoen
dc.okm.affiliatedauthorRuohonen, Jukka
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.relation.conferenceSoftware Quality Analysis, Monitoring, Improvement, and Applications
dc.relation.ispartofjournalCEUR Workshop Proceedings
dc.relation.volume2217
dc.source.identifierhttps://www.utupub.fi/handle/10024/167661
dc.titleA Case-Control Study on the Server-Side Bandages Against XSS
dc.title.bookProceedings of the Seventh Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications
dc.year.issued2018

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
paper-ruo.pdf
Size:
717.39 KB
Format:
Adobe Portable Document Format
Description:
Publisher's PDF