Auto-patching DOM-based XSS at scale
Abstract
DOM-based cross-site scripting (XSS) is a client-side code injection vulnerability that results from unsafe dynamic code generation in JavaScript applications, and has few known practical defenses. We study dynamic code evaluation practices on nearly a quarter million URLs crawled starting from the the Alexa Top 1000 websites. Of 777,082 cases of dynamic HTML/JS code generation we observe, 13.3% use unsafe string interpolation for dynamic code generation — a well-known dangerous coding practice. To remedy this, we propose a technique to generate secure patches that replace unsafe string interpolation with safer code that utilizes programmatic DOM construction techniques. Our system transparently auto-patches the vulnerable site while incurring only 5.2 − 8.07% overhead. The patching mechanism requires no access to server-side code or modification to browsers, and thus is practical as a turnkey defense.
BibTeX
@inproceedings{Parameshwaran-al:FSE15,
author = {Inian Parameshwaran and
Enrico Budianto and
Shweta Shinde and
Hung Dang and
Atul Sadhu and
Prateek Saxena},
title = {Auto-patching {DOM-based} {XSS} at scale},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {272--283},
publisher = {{ACM}},
year = {2015},
}