{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T06:45:37Z","timestamp":1764225937599,"version":"3.40.3"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031541285"},{"type":"electronic","value":"9783031541292"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_27","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"459-475","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["The Nonce-nce of\u00a0Web Security: An Investigation of\u00a0CSP Nonces Reuse"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8743-0825","authenticated-orcid":false,"given":"Matteo","family":"Golinelli","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Bonomi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1252-8465","authenticated-orcid":false,"given":"Bruno","family":"Crispo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"27_CR1","doi-asserted-by":"publisher","unstructured":"Calzavara, S., Rabitti, A., Bugliesi, M.: Content security problems? evaluating the effectiveness of content security policy in the wild. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 1365\u20131375. CCS \u201916, Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2976749.2978338","DOI":"10.1145\/2976749.2978338"},{"key":"27_CR2","unstructured":"Calzavara, S., Rabitti, A., Bugliesi, M.: CCSP: Controlled relaxation of content security policies by runtime policy composition. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 695\u2013712. USENIX Association, Vancouver, BC (2017). https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/calzavara"},{"key":"27_CR3","doi-asserted-by":"publisher","unstructured":"Calzavara, S., Rabitti, A., Bugliesi, M.: Semantics-based analysis of content security policy deployment. ACM Trans. Web 12(2) (2018). https:\/\/doi.org\/10.1145\/3149408","DOI":"10.1145\/3149408"},{"key":"27_CR4","unstructured":"CloudFront, A.: Understanding the cache key (2023). https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/understanding-the-cache-key.html"},{"key":"27_CR5","doi-asserted-by":"publisher","unstructured":"Doup\u00e9, A., Cui, W., Jakubowski, M.H., Peinado, M., Kruegel, C., Vigna, G.: Dedacota: toward preventing server-side xss via automatic code and data separation. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security. p. 1205\u20131216. CCS \u201913, Association for Computing Machinery, New York, NY, USA (2013). https:\/\/doi.org\/10.1145\/2508859.2516708","DOI":"10.1145\/2508859.2516708"},{"key":"27_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1007\/978-3-319-20550-2_14","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"D Hausknecht","year":"2015","unstructured":"Hausknecht, D., Magazinius, J., Sabelfeld, A.: May I? - content security policy endorsement for browser extensions. In: Almgren, M., Gulisano, V., Maggi, F. (eds.) DIMVA 2015. LNCS, vol. 9148, pp. 261\u2013281. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-20550-2_14"},{"issue":"3","key":"27_CR7","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1016\/j.jisa.2014.03.007","volume":"19","author":"M Johns","year":"2014","unstructured":"Johns, M.: Script-templates for the content security policy. J. Inf. Secur. Appl. 19(3), 209\u2013223 (2014). https:\/\/doi.org\/10.1016\/j.jisa.2014.03.007","journal-title":"J. Inf. Secur. Appl."},{"key":"27_CR8","doi-asserted-by":"publisher","unstructured":"Kerschbaumer., C., Stamm., S., Brunthaler., S.: Injecting CSP for fun and security. In: Proceedings of the 2nd International Conference on Information Systems Security and Privacy - ICISSP, pp. 15\u201325. INSTICC, SciTePress, Online (2016). https:\/\/doi.org\/10.5220\/0005650100150025","DOI":"10.5220\/0005650100150025"},{"key":"27_CR9","doi-asserted-by":"publisher","unstructured":"Lekies, S., Kotowicz, K., Gro\u00df, S., Vela Nava, E.A., Johns, M.: Code-reuse attacks for the web: breaking cross-site scripting mitigations via script gadgets. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1709\u20131723. CCS \u201917, Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3133956.3134091","DOI":"10.1145\/3133956.3134091"},{"key":"27_CR10","unstructured":"Mirheidari, S.A., Golinelli, M., Onarlioglu, K., Kirda, E., Crispo, B.: Web cache deception escalates! In: 31st USENIX Security Symposium (USENIX Security 22), pp. 179\u2013196. USENIX Association, Boston, MA (2022). https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/mirheidari"},{"issue":"12","key":"27_CR11","doi-asserted-by":"publisher","first-page":"993","DOI":"10.1145\/359657.359659","volume":"21","author":"RM Needham","year":"1978","unstructured":"Needham, R.M., Schroeder, M.D.: Using encryption for authentication in large networks of computers. Commun. ACM 21(12), 993\u2013999 (1978). https:\/\/doi.org\/10.1145\/359657.359659","journal-title":"Commun. ACM"},{"key":"27_CR12","unstructured":"OWASP: Cross Site Scripting Prevention Cheat Sheet. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross_Site_Scripting_Prevention_Cheat_Sheet.html"},{"key":"27_CR13","doi-asserted-by":"publisher","unstructured":"Pan, X., Cao, Y., Liu, S., Zhou, Y., Chen, Y., Zhou, T.: CSPAutoGen: black-box enforcement of content security policy upon real-world websites. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 653\u2013665. CCS \u201916, Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2976749.2978384","DOI":"10.1145\/2976749.2978384"},{"key":"27_CR14","unstructured":"Patil, K., Frederik, B.: A measurement study of the content security policy on real-world applications. Int. J. Netw. Secur. 18, 383\u2013392 (2016)"},{"key":"27_CR15","doi-asserted-by":"publisher","unstructured":"Pochat, V.L., Goethem, T.V., Tajalizadehkhoob, S., Korczynski, M., Joosen, W.: Tranco: a research-oriented top sites ranking hardened against manipulation. In: Proceedings 2019 Network and Distributed System Security Symposium. Internet Society (2019). https:\/\/doi.org\/10.14722\/ndss.2019.23386","DOI":"10.14722\/ndss.2019.23386"},{"key":"27_CR16","doi-asserted-by":"crossref","unstructured":"Roth, S., Barron, T., Calzavara, S., Nikiforakis, N., Stock, B.: Complex security policy? A longitudinal analysis of deployed content security policies. In: Proceedings of the 27th Network and Distributed System Security Symposium (2020)","DOI":"10.14722\/ndss.2020.23046"},{"key":"27_CR17","doi-asserted-by":"publisher","unstructured":"Roth, S., Gr\u00f6ber, L., Backes, M., Krombholz, K., Stock, B.: 12 Angry developers - a qualitative study on developers\u2019 struggles with CSP. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 3085\u20133103. CCS \u201921, Association for Computing Machinery, New York, NY, USA (2021). https:\/\/doi.org\/10.1145\/3460120.3484780","DOI":"10.1145\/3460120.3484780"},{"key":"27_CR18","doi-asserted-by":"publisher","unstructured":"Some, D.F., Bielova, N., Rezk, T.: On the content security policy violations due to the same-origin policy. In: Proceedings of the 26th International Conference on World Wide Web, pp. 877\u2013886. WWW \u201917, International World Wide Web Conferences Steering Committee, Republic and Canton of Geneva, CHE (2017). https:\/\/doi.org\/10.1145\/3038912.3052634","DOI":"10.1145\/3038912.3052634"},{"key":"27_CR19","doi-asserted-by":"publisher","unstructured":"Stamm, S., Sterne, B., Markham, G.: Reining in the web with content security policy. In: Proceedings of the 19th International Conference on World Wide Web, pp. 921\u2013930. WWW \u201910, Association for Computing Machinery, New York, NY, USA (2010). https:\/\/doi.org\/10.1145\/1772690.1772784","DOI":"10.1145\/1772690.1772784"},{"key":"27_CR20","doi-asserted-by":"crossref","unstructured":"Steffens, M., Musch, M., Johns, M., Stock, B.: Who\u2019s hosting the block party? Studying third-party blockage of CSP and SRI. In: Network and Distributed System Security Symposium (2021)","DOI":"10.14722\/ndss.2021.24028"},{"key":"27_CR21","doi-asserted-by":"crossref","unstructured":"Trampert, L., Stock, B., Roth, S.: Honey, I cached our security tokens re-usage of security tokens in the wild. RAID \u201923 (2023). https:\/\/swag.cispa.saarland\/papers\/trampert2023honey.pdf","DOI":"10.1145\/3607199.3607223"},{"key":"27_CR22","doi-asserted-by":"publisher","unstructured":"Van Acker, S., Hausknecht, D., Sabelfeld, A.: Data exfiltration in the face of CSP. In: Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security, pp. 853\u2013864. ASIA CCS \u201916, Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2897845.2897899","DOI":"10.1145\/2897845.2897899"},{"key":"27_CR23","unstructured":"Veditz, D., Barth, A., West, M.: Content security policy level 2. W3C recommendation, W3C (2016). https:\/\/www.w3.org\/TR\/2016\/REC-CSP2-20161215\/"},{"key":"27_CR24","doi-asserted-by":"publisher","unstructured":"Weichselbaum, L., Spagnuolo, M., Lekies, S., Janc, A.: CSP is dead, long live CSP! on the insecurity of whitelists and the future of content security policy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 1376\u20131387. CCS \u201916, Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2976749.2978363","DOI":"10.1145\/2976749.2978363"},{"key":"27_CR25","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1007\/978-3-319-11379-1_11","volume-title":"Research in Attacks, Intrusions and Defenses","author":"M Weissbacher","year":"2014","unstructured":"Weissbacher, M., Lauinger, T., Robertson, W.: Why is CSP failing? trends and challenges in CSP adoption. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) Research in Attacks, Intrusions and Defenses, pp. 212\u2013233. Springer International Publishing, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_11"},{"key":"27_CR26","unstructured":"West, M., Sartori, A.: Content security policy level 3. W3C working draft, W3C (2023). https:\/\/www.w3.org\/TR\/2023\/WD-CSP3-20230220\/"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:06:56Z","timestamp":1710194816000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}