ZigZag: automatically hardening web applications against client-side validation vulnerabilities
Michael Weissbacher, William Robertson, Engin Kirda, Christopher Kruegel, Giovanni Vigna · 2015
Modern web applications are increasingly moving pro-gram code to the client in the form of JavaScript. With the growing adoption of HTML5APIs such as postMessage, client-side validation (CSV) vulnerabilities are conse-quently becoming increasingly important to address as well. However, while detecting and preventing attacks against web applications is a well-studied topic on the server, considerably less work has been performed for the client. Exacerbating this issue is the problem that de-fenses against CSVsmust, in the general case, fundamen-tally exist in the browser, rendering current server-side defenses inadequate. In this paper, we present ZigZag, a system for hard-ening JavaScript-based web applications against client-side validation attacks. ZigZag transparently instru-ments client-side code to perform dynamic invariant de-tection on security-sensitive code, generating models that describe how – and with whom – client-side com-ponents interact. ZigZag is capable of handling tem-plated JavaScript, avoiding full re-instrumentation when JavaScript programs are structurally similar. Learned in-variants are then enforced through a subsequent instru-mentation step. Our evaluation demonstrates that ZigZag is capable of automatically hardening client-side code against both known and previously-unknown vulnerabil-ities. Finally, we show that ZigZag introduces acceptable overhead in many cases, and is compatible with popular websites drawn from the Alexa Top 20 without developer or user intervention. 1