JSand: complete client-side sandboxing of third-party JavaScript without browser modifications

JSand: complete client-side sandboxing of third-party JavaScript without browser modifications
复制标题

DOI:
10.1145/2420950.2420952
复制
发表时间:
2012-12
期刊:
--
影响因子:
--
通讯作者:
Pieter Agten;S. Acker;Yoran Brondsema;Phu H. Phung;Lieven Desmet;Frank Piessens
Pieter Agten;S. Acker;Yoran Brondsema;Phu H. Phung;Lieven Desmet;Frank Piessens
中科院分区:
其他
文献类型:
--
作者:
Pieter Agten;S. Acker;Yoran Brondsema;Phu H. Phung;Lieven Desmet;Frank Piessens

文献摘要

被引文献

相似文献

在网页中包含第三方脚本是一种常见的做法。最近的一项研究表明,Alexa排名前10000位的网站中有一半以上包含来自5个以上不同来源的脚本。然而,这种脚本包含有风险,因为包含的脚本使用包含网站的权限进行操作。我们提出了JSand,一个服务器驱动但客户端JavaScript沙箱框架。JSand不需要修改浏览器:沙盒框架是用JavaScript实现的,并由使用它的网站交付给浏览器。执行完全在客户端完成:JSand对包含的脚本执行服务器指定的策略,而不需要服务器端过滤或重写脚本。最重要的是,JSand是完整的:对所有资源的访问都是通过沙箱进行的。我们描述了JSand的设计和实现,我们证明了它是安全的,向后兼容的,并且它表现得足够好。
The inclusion of third-party scripts in web pages is a common practice. A recent study has shown that more than half of the Alexa top 10000 sites include scripts from more than 5 different origins. However, such script inclusions carry risks, as the included scripts operate with the privileges of the including website. We propose JSand, a server-driven but client-side JavaScript sandboxing framework. JSand requires no browser modifications: the sandboxing framework is implemented in JavaScript and is delivered to the browser by the websites that use it. Enforcement is done entirely at the client side: JSand enforces a server-specified policy on included scripts without requiring server-side filtering or rewriting of scripts. Most importantly, JSand is complete: access to all resources is mediated by the sandbox. We describe the design and implementation of JSand, and we show that it is secure, backwards compatible, and that it performs sufficiently well.