ConScript: Specifying and Enforcing Fine-Grained Security Policies for JavaScript in the Browser

ConScript: Specifying and Enforcing Fine-Grained Security Policies for JavaScript in the Browser
复制标题

DOI:
10.1109/sp.2010.36
复制
发表时间:
2010-05
期刊:
2010 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Leo A. Meyerovich;B. Livshits
Leo A. Meyerovich;B. Livshits
中科院分区:
其他
文献类型:
--
作者:
Leo A. Meyerovich;B. Livshits

文献摘要

被引文献

相似文献

现代Web的大部分功能来自于Web页面将来自不同服务器的联合收割机内容和JavaScript代码组合在同一页面上的能力。虽然创建这种混搭的能力对用户和开发人员都很有吸引力,因为它具有额外的功能,但代码包含有效地打开了托管站点,使其在选择使用的每个JavaScript库或API中受到攻击和不良编程实践。换句话说,表现力是以失去控制为代价的。因此,为了重新获得控制权,为宿主页面提供限制页面可能包含的代码行为的方法是有价值的。本文介绍了ConScript,一个客户端的安全建议实现,建立在Internet Explorer 8之上。ConScript允许宿主页面表达在运行时实施的细粒度应用程序特定的安全策略。除了介绍ConScript支持的17种广泛的安全性和可靠性策略外,我们还展示了如何通过服务器端代码的静态分析或客户端代码的运行时分析自动生成策略。我们还提出了一个类型系统,有助于确保ConScript策略的正确性。为了展示ConScript在一系列设置中的实用性,我们比较了ConScript执行的开销,并得出结论,无论是在微基准测试还是在大型的、广泛使用的应用程序(如MSN、Gmail、Google地图和Live Desktop)上,它都明显低于文献中提出的其他系统。
Much of the power of modern Web comes from the ability of a Web page to combine content and JavaScript code from disparate servers on the same page. While the ability to create such mash-ups is attractive for both the user and the developer because of extra functionality, code inclusion effectively opens the hosting site up for attacks and poor programming practices within every JavaScript library or API it chooses to use. In other words, expressiveness comes at the price of losing control. To regain the control, it is therefore valuable to provide means for the hosting page to restrict the behavior of the code that the page may include. This paper presents ConScript, a client-side advice implementation for security, built on top of Internet Explorer 8. ConScript allows the hosting page to express fine-grained application-specific security policies that are enforced at runtime. In addition to presenting 17 widely-ranging security and reliability policies that ConScript enables, we also show how policies can be generated automatically through static analysis of server-side code or runtime analysis of client-side code. We also present a type system that helps ensure correctness of ConScript policies. To show the practicality of ConScript in a range of settings, we compare the overhead of ConScript enforcement and conclude that it is significantly lower than that of other systems proposed in the literature, both on micro-benchmarks as well as large, widely-used applications such as MSN, GMail, Google Maps, and Live Desktop.