Reining in the Web with Content Security Policy¶
Stamm, S., Sterne, B., & Markham, G. (2010). Reining in the Web with Content Security Policy. Proceedings of the 19th International Conference on World Wide Web, 921-930.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Content Security Policy or Execution Policy
- Its strength is precisely that it is a second line: it limits the damage of an injection the primary controls missed, which is the whole point of defense in depth, and it does so declaratively, without inspecting content for badness.
This sourcePresents CSP as a declarative, browser-enforced second layer that constrains injected content missed by primary validation controls.
- Its strength is precisely that it is a second line: it limits the damage of an injection the primary controls missed, which is the whole point of defense in depth, and it does so declaratively, without inspecting content for badness.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:0a67936b02ac · see in the full table