Multiple facets for dynamic information flow

Multiple facets for dynamic information flow
复制标题

DOI:
10.1145/2103656.2103677
复制
发表时间:
2012-01
期刊:
--
影响因子:
--
通讯作者:
Thomas H. Austin;C. Flanagan
Thomas H. Austin;C. Flanagan
中科院分区:
其他
文献类型:
--
作者:
Thomas H. Austin;C. Flanagan

文献摘要

被引文献

相似文献

JavaScript已成为网络的中心技术,但它也是许多安全问题的根源,包括跨站点脚本攻击和恶意广告代码。这些问题的核心是,来自不受信任的来源的代码具有完全特权。我们在Firefox中实施信息流控制,以防止违反数据机密性和完整性。大多数以前的信息流动技术主要依赖于静态类型系统,该系统适合JavaScript,或者是由于有问题的隐性流而有时会陷入的动态分析,即使在目标Web应用程序正确满足所需的安全策略的情况下, 。我们介绍了面值,这是一种以动态方式提供信息流安全性的新机制,以克服这些限制。从安全的多执行中汲取灵感,我们使用刻面值同时有效地模拟了不同的安全级别的多个执行,从而提供了最小的间接费用,而无需依赖于先前动态方法的卡住执行。
JavaScript has become a central technology of the web, but it is also the source of many security problems, including cross-site scripting attacks and malicious advertising code. Central to these problems is the fact that code from untrusted sources runs with full privileges. We implement information flow controls in Firefox to help prevent violations of data confidentiality and integrity. Most previous information flow techniques have primarily relied on either static type systems, which are a poor fit for JavaScript, or on dynamic analyses that sometimes get stuck due to problematic implicit flows, even in situations where the target web application correctly satisfies the desired security policy. We introduce faceted values, a new mechanism for providing information flow security in a dynamic manner that overcomes these limitations. Taking inspiration from secure multi-execution, we use faceted values to simultaneously and efficiently simulate multiple executions for different security levels, thus providing non-interference with minimal overhead, and without the reliance on the stuck executions of prior dynamic approaches.