A4 Refereed article in a conference publication

A Case-Control Study on the Server-Side Bandages Against XSS




AuthorsRuohonen J., Leppänen V.

EditorsZoran Budimac

Conference nameSoftware Quality Analysis, Monitoring, Improvement, and Applications

PublisherCEUR-WS

Publication year2018

JournalCEUR Workshop Proceedings

Book title Proceedings of the Seventh Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications

Journal name in sourceCEUR Workshop Proceedings

Volume2217

ISBN978-86-7031-473-3

ISSN1613-0073

Web address http://ceur-ws.org/Vol-2217/paper-ruo.pdf

Self-archived copy’s web addresshttps://research.utu.fi/converis/portal/detail/Publication/36035085


Abstract

This paper surveys the server-side use of security-related options for protecting websites against cross-site scripting (XSS) attacks. By using data from a bug bounty platform, the use of these header-based options is approached with a case-control study that contrasts popular Internet domains against less popular domains that have explicitly been veried to have been vulnerable to XSS. According to the results based on the analysis of nearly 800 thousand domains, (a) the header-based security options are only infrequently used. However, (b) the domains known to have been vulnerable to XSS have been much less likely to use these options compared to popular domains. Furthermore, (c) the options surveyed tend to statistically form clear latent dimensions, which can be speculated to relate to the eort required to enforce strict security policies for websites.


Downloadable publication

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 12:15