Object Capabilities and Isolation of Untrusted Web Applications

Object Capabilities and Isolation of Untrusted Web Applications
复制标题

DOI:
10.1109/sp.2010.16
复制
发表时间:
2010-05
期刊:
2010 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
S. Maffeis;John C. Mitchell;Ankur Taly
S. Maffeis;John C. Mitchell;Ankur Taly
中科院分区:
其他
文献类型:
--
作者:
S. Maffeis;John C. Mitchell;Ankur Taly

文献摘要

相似文献

越来越多的当前网站将来自不可信来源的活动内容(应用程序)组合在一起,就像所谓的mashup一样。对象能力模型为隔离不受信任的内容提供了一种吸引人的方法:如果单独的应用程序提供了不相关的功能,那么一个健全的对象能力框架应该防止不受信任的应用程序相互干扰,而不会阻止与用户或托管页面的交互。在开发基于对象能力概念的隔离证明的基于语言的基础时,我们确定了一个更一般的权威安全概念,它也意味着资源隔离。在证明了功能安全意味着权限安全之后,我们将展示我们的框架对特定mashup类的适用性。除了证明基于谷歌Caja的JavaScript子集是功能安全的之外,我们还证明了更具表现力的JavaScript子集是权限安全的,即使它不是基于对象-功能模型。
A growing number of current web sites combine active content (applications) from untrusted sources, as in so-called mashups. The object-capability model provides an appealing approach for isolating untrusted content: if separate applications are provided disjoint capabilities, a sound object-capability framework should prevent untrusted applications from interfering with each other, without preventing interaction with the user or the hosting page. In developing language-based foundations for isolation proofs based on object-capability concepts, we identify a more general notion of authority safety that also implies resource isolation. After proving that capability safety implies authority safety, we show the applicability of our framework for a specific class of mashups. In addition to proving that a JavaScript subset based on Google Caja is capability safe, we prove that a more expressive subset of JavaScript is authority safe, even though it is not based on the object-capability model.