课题基金 / 基金详情

TWC: Small: New Foundations for Secure JavaScript

TWC: Small: New Foundations for Secure JavaScript
TWC:小型:安全 JavaScript 的新基础
批准号:
1223850
负责人:
Ranjit Jhala
金额:
$40.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-01 至 2017-08-31

项目摘要

项目成果

Ranjit Jhala的其他基金

相似基金

相关文献

中文摘要
翻译
JavaScript改变了软件系统的开发、部署和扩展方式。它现在被用来构建复杂的、安全敏感的应用程序,用于通信、零售和银行,甚至是Web浏览器本身的主要构建块。不幸的是,随着应用程序操纵浏览历史、密码、银行账号、社保号码等安全关键客户端信息,JavaScript的出现也为新类别的安全漏洞打开了大门。更糟糕的是,缺乏语言级别的隔离机制,使得关键软件组件的保密性和完整性很难建立。我们认为,使Web更安全的关键是开发一个实用、准确和可表达的类型系统,并将其作为开发Java浏览器扩展和应用程序的安全策略、分析和执行机制的基础。因此,我们建议为JavaScript开发一个类型系统,该系统具有足够的表现力来支持JavaScript的动态习惯用法,足够实用,可以最大限度地减少程序员的干预,因此能够高度自动化地分析大型代码库,并且足够容易地扩展到允许开发人员指定和实施不同类型的细粒度安全策略。我们的研究将导致以下贡献:最终用户将能够从受信任的站点自由运行扩展、插件和丰富的浏览器应用程序,而不必遭受代码注入、信息外泄或完全动态实施的令人不快的治疗方法的困扰,这些开销可能会导致站点无法使用。开发人员将能够在熟悉的包中充分享受静态验证的成果:即类型。类型将允许开发人员以适当的粒度指定某些功能所需的权限,并将防止因过度设置或数据清理不足而引入的无意漏洞。聚合第三方应用程序(例如各种移动平台的“应用程序商店”)的管理员将能够使用基于类型的证书来快速审查应用程序,从而在不损害平台声誉的情况下确定应用程序是否可以安全托管。
英文摘要
JavaScript has transformed the way in which software systems are developed, deployed and extended. It is now used to build complex, security sensitive applications for communications, retail, and banking, and is even a primary building block of web browsers themselves. Unfortunately, the advent of JavaScript has also opened the door to new classes of security vulnerabilities, as applications manipulate security critical client information like browsing history, passwords, bank account numbers, social security numbers and so on. Worse, the absence of language-level isolation mechanisms makes it hard to establish confidentiality and integrity of key software components.We believe that the key to making the web more secure is to develop a practical, precise and expressive type system for JavaScript and to use it as a foundation for developing security policies, analyses and enforcement mechanisms for JavaScript browser extensions and applications. Thus, we propose to develop a type system for JavaScript that is expressive enough to support JavaScript's dynamic idioms, practical enough to require minimal programmer intervention and hence, be capable of highly automated analysis of large code bases, and easily extensible enough to allow developers to specify and enforce different kinds of fine-grained security policies.Our research will lead to the following contributions: End Users will be able to freely run extensions, plugins and rich browser applications from trusted sites, without having to suffer the plagues of code-injection, information exfiltration or the unpalatable cures of fully dynamic enforcement whose overhead can render sites unusable. Developers will be able to fully enjoy the fruits of static verification, in a familiar package: namely types. Types will allow developers to specify at the right granularity, the permissions required for some functionality, and will prevent the inadvertent vulnerabilities that are introduced by overprovisioning, or under-sanitization of data. Curators that aggregate third party applications (e.g. ``app stores" for various mobile platforms) will be able to use type-based certificates to quickly vet applications, thereby determining if an application is safe to host without compromising the reputation of the platform.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SHF: Small: Collaborative research: Language-Integrated Verification for Determininistic Parallelism
  • 批准号:
    1911213
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2019
  • 负责人:
    Ranjit Jhala
  • 依托单位:
FMitF: Track II: Refinement Types in the Haskell Ecosystem
  • 批准号:
    1917854
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2019
  • 负责人:
    Ranjit Jhala
  • 依托单位:
SHF: Medium: Collaborative Research: Program Analytics: Using Trace Data for Localization, Explanation and Synthesis
  • 批准号:
    1763814
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $90.0万
  • 财政年份:
    2018
  • 负责人:
    Ranjit Jhala
  • 依托单位:
TWC: Medium: Detection and Prevention of Data Timing Channels
  • 批准号:
    1514435
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2015
  • 负责人:
    Ranjit Jhala
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: