Dynamic Content Security Policy Generation at Client-Side to Mitigate XSS Attacks

No Thumbnail Available

Date

2024

Journal Title

Journal ISSN

Volume Title

Publisher

Institute of Electrical and Electronics Engineers Inc.

Abstract

Cross-site scripting (XSS) attacks are a major threat to web applications and have consistently ranked among the OWASP Top 10 vulnerabilities. Attackers can inject malicious scripts that execute within a user's browser. Server-side Content Security Policies (CSPs) offer some protection, but their static nature makes them ineffective when dealing with dynamic content and a very small percentage of web application use. This paper explores dynamically generated CSPs on the client side. This approach overcomes the limitations of traditional CSPs and provides a more robust defense against XSS attacks. © 2024 IEEE.

Description

Keywords

Content Security Policy (CSP), Cross-site scripting (XSS) attacks, data injection, OWASP Top 10 vulnerabilities

Citation

2024 15th International Conference on Computing Communication and Networking Technologies, ICCCNT 2024, 2024, Vol., , p. -

Endorsement

Review

Supplemented By

Referenced By