Evaluating website security: a study on content security policy implementation

dc.contributor.authorFernandes de Oliveira, Isabella
dc.contributor.authorRen, Mengxia
dc.date2024-04
dc.date.accessioned2024-05-08T22:04:36Z
dc.date.available2024-05-08T22:04:36Z
dc.description.abstractContent Security Policies (CSPs) are vital defenses against cross-site scripting (XSS) and unauthorized web resource manipulation. This study investigates CSP implementation across the top 100 websites listed in TRANCO, focusing on resilience to external manipulation. Our analysis reveals that over 50% of domains lack adequate protection against XSS attacks, despite CSP implementation. Vulnerabilities include the misuse of 'unsafe-inline' directives and reliance on white-listing-based policies over nonce-based alternatives. These findings highlight the need for a comprehensive CSP approach, prioritizing script and web control. Strategies to enhance website security, such as stricter CSP configurations, are discussed, emphasizing nonce-based strategies and comprehensive directive coverage.
dc.format.mediumposters
dc.identifier.urihttps://hdl.handle.net/11124/179051
dc.identifier.urihttps://doi.org/10.25676/11124/179051
dc.languageEnglish
dc.language.isoeng
dc.publisherColorado School of Mines. Arthur Lakes Library
dc.relation.ispartof2024 Spring Undergraduate Research Symposium
dc.rightsCopyright of the original work is retained by the author.
dc.titleEvaluating website security: a study on content security policy implementation
dc.typeText
dc.typeStillImage
dspace.entity.typePublication
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Fernandes_D_Isabella_UGRS2024.pdf
Size:
408.22 KB
Format:
Adobe Portable Document Format