Object Capabilities and Isolation of Untrusted Web Applications
Object Capabilities and Isolation of Untrusted Web Applications
复制标题
DOI:
10.1109/sp.2010.16
复制
发表时间:
2010-05
期刊:
影响因子:
--
通讯作者:
S. Maffeis;John C. Mitchell;Ankur Taly
中科院分区:
文献类型:
--
作者:
S. Maffeis;John C. Mitchell;Ankur Taly
A growing number of current web sites combine active content (applications) from untrusted sources, as in so-called mashups. The object-capability model provides an appealing approach for isolating untrusted content: if separate applications are provided disjoint capabilities, a sound object-capability framework should prevent untrusted applications from interfering with each other, without preventing interaction with the user or the hosting page. In developing language-based foundations for isolation proofs based on object-capability concepts, we identify a more general notion of authority safety that also implies resource isolation. After proving that capability safety implies authority safety, we show the applicability of our framework for a specific class of mashups. In addition to proving that a JavaScript subset based on Google Caja is capability safe, we prove that a more expressive subset of JavaScript is authority safe, even though it is not based on the object-capability model.