Mocha: Automatically Applying Content Security Policy to HTML Hybrid Application on Android Device
Toshiki Takeuchi, Koichi Mouri, Shoichi Saito · 2017
An HTML hybrid application is a type of application running on mobile devices. It is popular but may have Cross Site Scripting(XSS) vulnablitiy risks. Content Security Policy(CSP) is a security mechanism that can prevent XSS attacks. Developers can only apply CSP to applications, therefore user's safety depends on them. In this paper, we propose Mocha, automatically applying CSP to applications on the Android device. Mocha uses static analysis to automatically infer CSP policies, and modifies HTML and JavaScript source code for applying CSP. Mocha can protect users and their HTML hybrid applications from XSS. We confirmed that Mocha is effective with real applications.