XAS:Cross-API scripting attacks in social ecosystems

来源 :Science China(Information Sciences) | 被引量 : 0次 | 上传用户:sxtld
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
With the rapid development of online social networks, various Web application programming interfaces(APIs) on social platforms are released to share profitable social data with all kinds of third-party online services. However, it also brings new risks to social networks once Web APIs are insecurely designed,implemented, and invoked. The focused topic in this paper is security analysis of a new type of cross-site scripting(XSS) which is based on Web APIs in new complicated social ecosystems which consist of social networks,third-party apps, and other online services. In this paper, we refer to Web API-based XSS as cross-API scripting(XAS). For the first time, we take typical XAS attacks in diversified context as cases to demonstrate the new exploiting opportunities and threats in social ecosystems. Also, we design a tool to identify the design and implementation flaws of Web APIs in 11 popular social networks. We discover several security flaws of API via our experiment. According to the results, we conclude causes of XAS flaws in depth. We also examined 143Web-based apps and verified the prevalence of XAS flaws. Finally, we proposed preliminary measures both in social networks and third-party applications to alleviate XAS. With the rapid development of online social networks, various web application programming interfaces (APIs) on social platforms are released to share profitable social data with all kinds of third-party online services. However, it also brings new risks to social networks once Web APIs are insecurely designed, implemented, and invoked. The focused topic in this paper is security analysis of a new type of cross-site scripting (XSS) which is based on Web APIs in new complicated social ecosystems which consist of social networks, third-party apps, and other online services. In this paper, we refer to Web API-based XSS as cross-API scripting (XAS). For the first time, we take typical XAS attacks in diversified context as cases to demonstrate the new exploit opportunities and Also, we design a tool to identify the design and implementation flaws of Web APIs in 11 popular social networks. We discover several security flaws of API via our experiment. According to t We also examine 143 Web-based apps and verified the prevalence of XAS flaws. Finally, we propose preliminary measures both in social networks and third-party applications to alleviate XAS.
其他文献
近几年来,一种敏感的免疫金银染色(immunogold—silver staining, IGSS)方法在免疫组织化学研究中得到了应用。我们用一种新的石蜡包埋方法将不同的组织包埋在一个蜡块中,在
1颓废型这种男人不求上进,只知道抽烟喝酒睡觉。嫁他一定没好日子过,说不定他还等着你养他呢! 2阴险型你永远不会知道他打的是什么算盘,你们的关系完全掌握在他手中,说不定哪
期刊
男性真的对性感到苦恼吗?他们何时达到他们的性喜峰呢?没有男性会将这样的秘密告诉你。男性性欲的误区即使知识广博的夫妇,对性也会有些误解口只有消除了误解,性生活才会变得
目的了解无锡市锡山区肺结核的流行特点和规律,为制定结核病防治策略提供依据。方法对锡山区2007-2012年肺结核病的登记资料,应用流行病学方法进行分析。结果锡山区2007-2012
我厂研制的定位输送机具有两个动作,见图1。转盘缸Ⅰ把输送机由原位置a 转到工作位霞b,齿条缸Ⅱ驱动齿轮及同轴上的链轮,带动链条把放在链头前的物体输送1.5m。然后,齿条缸
乳腺癌是危害女性健康的主要肿瘤,目前还没有特定的方法及生物标记物能够在早期发现及诊断。蛋白质组学通过对蛋白质动态的分析可以在疾病早期发现最微小的指标和征兆,从而发
制造出售光电子机器的竹中系统机器公司从去年8月份开始正式出售超高灵敏度的CCD微光摄像机。该公司的CCD微光摄像机的最低照度为0.3mlx,可在夜间10~(-3)勒克斯的星光照度下
嗜碱粒细胞是血液内含有嗜碱颗粒的细胞,肥大细胞则是结缔组织内含有大量嗜碱性颗粒的细胞。目前已知,嗜碱粒细胞和肥大细胞它们所含有的颗粒物质和功能十分相似,因此两者统
现代都市,亚婚姻状态正在蔓延。许多家庭虽然在形式上维持着完整的外壳,但是男女双方却无话可说,勉强凑合。在婚姻的围城里,很多人的热情正在下降,爱情也逐渐流失,婚姻已经
原发性肝癌(HCC)是我国最常见的恶性肿瘤之一,乙型肝炎病毒(HBV)X蛋白和丙型肝炎病毒(HCV)核心蛋白可通过影响肝细胞内信号传导及细胞凋亡等机制,调节某些基因的转录及表达,