Mitigating cross-site scripting attacks with a content security Policy

A content security policy (CSP) can help Web application developers and server administrators better control website content and avoid vulnerabilities to cross-site scripting (XSS). In experiments with a prototype website, the authors' CSP implementation successfully mitigated all XSS attack ty...

Full description

Bibliographic Details
Main Authors: Yusof, Imran, Pathan, Al Sakib Khan
Format: Article
Language:English
English
Published: IEEE Computer Society 2016
Subjects:
Online Access:http://irep.iium.edu.my/58853/
http://irep.iium.edu.my/58853/1/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_article.pdf
http://irep.iium.edu.my/58853/2/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_scopus.pdf
_version_ 1848785194403758080
author Yusof, Imran
Pathan, Al Sakib Khan
author_facet Yusof, Imran
Pathan, Al Sakib Khan
author_sort Yusof, Imran
building IIUM Repository
collection Online Access
description A content security policy (CSP) can help Web application developers and server administrators better control website content and avoid vulnerabilities to cross-site scripting (XSS). In experiments with a prototype website, the authors' CSP implementation successfully mitigated all XSS attack types in four popular browsers.
first_indexed 2025-11-14T16:49:16Z
format Article
id iium-58853
institution International Islamic University Malaysia
institution_category Local University
language English
English
last_indexed 2025-11-14T16:49:16Z
publishDate 2016
publisher IEEE Computer Society
recordtype eprints
repository_type Digital Repository
spelling iium-588532017-10-21T06:03:47Z http://irep.iium.edu.my/58853/ Mitigating cross-site scripting attacks with a content security Policy Yusof, Imran Pathan, Al Sakib Khan QA76 Computer software TK Electrical engineering. Electronics Nuclear engineering TK5101 Telecommunication. Including telegraphy, radio, radar, television A content security policy (CSP) can help Web application developers and server administrators better control website content and avoid vulnerabilities to cross-site scripting (XSS). In experiments with a prototype website, the authors' CSP implementation successfully mitigated all XSS attack types in four popular browsers. IEEE Computer Society 2016-03 Article PeerReviewed application/pdf en http://irep.iium.edu.my/58853/1/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_article.pdf application/pdf en http://irep.iium.edu.my/58853/2/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_scopus.pdf Yusof, Imran and Pathan, Al Sakib Khan (2016) Mitigating cross-site scripting attacks with a content security Policy. Computer, 49 (3). pp. 56-63. ISSN 0018-9162 http://ieeexplore.ieee.org.ezlib.iium.edu.my/stamp/stamp.jsp?arnumber=7433336 10.1109/MC.2016.76
spellingShingle QA76 Computer software
TK Electrical engineering. Electronics Nuclear engineering
TK5101 Telecommunication. Including telegraphy, radio, radar, television
Yusof, Imran
Pathan, Al Sakib Khan
Mitigating cross-site scripting attacks with a content security Policy
title Mitigating cross-site scripting attacks with a content security Policy
title_full Mitigating cross-site scripting attacks with a content security Policy
title_fullStr Mitigating cross-site scripting attacks with a content security Policy
title_full_unstemmed Mitigating cross-site scripting attacks with a content security Policy
title_short Mitigating cross-site scripting attacks with a content security Policy
title_sort mitigating cross-site scripting attacks with a content security policy
topic QA76 Computer software
TK Electrical engineering. Electronics Nuclear engineering
TK5101 Telecommunication. Including telegraphy, radio, radar, television
url http://irep.iium.edu.my/58853/
http://irep.iium.edu.my/58853/
http://irep.iium.edu.my/58853/
http://irep.iium.edu.my/58853/1/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_article.pdf
http://irep.iium.edu.my/58853/2/58853_Mitigating%20Cross-Site%20Scripting%20Attacks%20_scopus.pdf