Protecting Users by Confining JavaScript with COWL

Protecting Users by Confining JavaScript with COWL
复制标题

DOI:
--
复制
发表时间:
2014-10
期刊:
--
影响因子:
--
通讯作者:
D. Stefan;Edward Z. Yang;Petr Marchenko;Alejandro Russo;David Herman;B. Karp;David Mazières
D. Stefan;Edward Z. Yang;Petr Marchenko;Alejandro Russo;David Herman;B. Karp;David Mazières
中科院分区:
其他
文献类型:
--
作者:
D. Stefan;Edward Z. Yang;Petr Marchenko;Alejandro Russo;David Herman;B. Karp;David Mazières

文献摘要

被引文献

相似文献

现代Web应用程序是由多个作者撰写的JavaScript的集团:应用程序开发人员通常合并第三方库中的代码,Mashup应用程序合成了在不同站点上托管的数据和代码。在当前浏览器中,Web应用程序的开发人员和用户必须在库中信任第三方代码,以免从应用程序内部泄露用户的敏感信息。更糟糕的是,在现状中,实施某些混搭的唯一方法是让用户将一个站点的登录凭据授予另一个站点的运营商。从根本上讲,当今的浏览器安全模型将隐私权用于灵活性,因为它缺乏足够的机制来限制不受信任的代码。我们提出了Cowl,这是一种可用于现代网络浏览器的强大JavaScript限制系统。 Cowl以与旧式网络内容完全倒退的方式引入了基于标签的强制性访问控制对浏览上下文的浏览上下文。我们使用一系列案例研究应用程序来激励Cowl的设计,并演示Cowl如何允许在应用程序中包含不信任的脚本和建立MASHUPS,这些混合物结合了来自多重不信任的起源的敏感信息,同时保护用户的隐私。两个cowl实现的测量,一个在Firefox中,一个在铬中,表明页面载延迟几乎不可察觉。
Modern web applications are conglomerations of JavaScript written by multiple authors: application developers routinely incorporate code from third-party libraries, and mashup applications synthesize data and code hosted at different sites. In current browsers, a web application's developer and user must trust third-party code in libraries not to leak the user's sensitive information from within applications. Even worse, in the status quo, the only way to implement some mashups is for the user to give her login credentials for one site to the operator of another site. Fundamentally, today's browser security model trades privacy for flexibility because it lacks a sufficient mechanism for confining untrusted code. We present COWL, a robust JavaScript confinement system for modern web browsers. COWL introduces label-based mandatory access control to browsing contexts in a way that is fully backward-compatible with legacy web content. We use a series of case-study applications to motivate COWL's design and demonstrate how COWL allows both the inclusion of untrusted scripts in applications and the building of mashups that combine sensitive information from multiple mutually distrusting origins, all while protecting users' privacy. Measurements of two COWL implementations, one in Firefox and one in Chromium, demonstrate a virtually imperceptible increase in page-load latency.