José Carlos Pazos

dblp:265/5554 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0001-9319-2256ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2023 XSnare: application-specific client-side cross-site scripting protection
José Carlos Pazos, Jean-Sébastien Légaré, Ivan Beschastnikh
Empir. Softw. Eng.1
2021 XSnare: Application-specific client-side cross-site scripting protection
abstract
We present XSnare, a client-side Cross-Site Scripting (XSS) solution implemented as a Firefox extension. The client-side design of XSnare can protect users before application developers release patches and before server operators apply them.XSnare blocks XSS attacks by using previous knowledge of a web application’s HTML template content and the rich DOM context. XSnare uses a database of exploit descriptions, which are written with the help of previously recorded CVEs. It singles out injection points for exploits in the HTML and dynamically sanitizes content to prevent malicious payloads from appearing in the DOM. XSnare displays a secured version of the site, even if is exploited.We evaluated XSnare on 81 recent CVEs related to XSS attacks, and found that it defends against 93.8% of these exploits. To the best of our knowledge, XSnare is the first protection mechanism for XSS that is application-specific, and based on publicly available CVE information. We show that XSnare’s specificity protects users against exploits which evade other, more generic, XSS defenses.Our performance evaluation shows that our extension’s overhead on web page loading time is less than 10% for 72.6% of the sites in the Moz Top 500 list.
José Carlos Pazos, Jean-Sébastien Légaré, Ivan Beschastnikh
SANER1