Dynamic Content Security Policy Generation at Client-Side to Mitigate XSS Attacks
No Thumbnail Available
Date
2024
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Institute of Electrical and Electronics Engineers Inc.
Abstract
Cross-site scripting (XSS) attacks are a major threat to web applications and have consistently ranked among the OWASP Top 10 vulnerabilities. Attackers can inject malicious scripts that execute within a user's browser. Server-side Content Security Policies (CSPs) offer some protection, but their static nature makes them ineffective when dealing with dynamic content and a very small percentage of web application use. This paper explores dynamically generated CSPs on the client side. This approach overcomes the limitations of traditional CSPs and provides a more robust defense against XSS attacks. © 2024 IEEE.
Description
Keywords
Content Security Policy (CSP), Cross-site scripting (XSS) attacks, data injection, OWASP Top 10 vulnerabilities
Citation
2024 15th International Conference on Computing Communication and Networking Technologies, ICCCNT 2024, 2024, Vol., , p. -
