JS: Lightweight Cross-Site Scripting Prevention Using Isolation Operators
Elias Athanasopoulos, Vasilis Pappas, Spyros Ligouras, Evangelos P. Markatos, Thomas Karagiannis · 2009
Cross-site scripting (XSS) attacks constitute one of the major threats for today’s web sites. Recently reported numbers on XSS vulnerabilities, coupled with the increasing complexity of modern web browsers, clearly highlight the need for effective mitigat ion mechanisms. However, despite the significance of these attacks, a definitive approach against any typ e of XSS vulnerability sill remains elusive. To further highlight this absence of effective countermeasures, we present a new family of code-injection attacks that defeat existing approaches for XSS prevention. The identified attacks resemble the classic return-to-libc attack in native code. To account for the detected vulnerabilities, we proceed and present a fast and practical mechanism, namely xJS, that isolates all legitimate client-side code from possib le code injections. xJS is a lightweight mechanism that is based on the concept of Instruction Set Randomization (ISR). We implement and evaluate our solution in three leading web browsers, namely FireFox, WebKit and Chromium, and in the Apache web server. We show that our framework can successfully prevent all 1,380 real-world attacks that were collected from a well-known XSS attack repository. Furthermore, our framework imposes negligible computational overhead in both the server and the client side, and has no negative side-effects in the overall user’s browsing experience.