课题基金 / 基金详情

SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality

SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality
SaTC:核心:媒介:协作:通过自动减少浏览器功能来驯服 Web 内容
批准号:
1703644
负责人:
Adam Doupe
金额:
$40.61万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2021-08-31

项目摘要

项目成果

Adam Doupe的其他基金

相似基金

相关文献

中文摘要
翻译
通过Web浏览器执行的基于Web的应用程序在日常生活中随处可见。它们构成了我们的银行、通信、购物、社交网络、纳税、保险交易和医疗保健互动的基础。不幸的是,恶意攻击者可以利用Web浏览器中的漏洞来攻击用户的计算机。Web浏览器攻击的后果可能很严重:Web内容可以在受害者的计算机上执行任意代码。该研究项目研究Web应用程序如何使用Web浏览器提供的功能,以及如何通过限制不必要的浏览器功能来保护用户系统。该项目通过减少浏览器功能足迹来解决Web浏览器的安全问题,从而减少浏览器攻击面,缓解多种类型的攻击。研究人员正在构建一种功能插装的浏览器,它可以报告Web应用程序使用了哪些功能。然后,他们利用这些信息自动识别Web应用程序偏离其预期行为并攻击用户浏览器的时间。为了使用户能够使用最新的浏览器,同时保护他们免受不必要的和有风险的浏览器功能的影响,研究团队正在构建一个将功能与浏览器分离的系统。
英文摘要
Web-based applications executed via web browsers are ubiquitous in everyday life. They underlie our banking, communications, shopping, social networking, tax payments, insurance transactions, and health care interactions. Unfortunately, malicious actors can take advantage of vulnerabilities in web browsers to exploit the user's computer. The consequences of a web browser attack can be severe: web content can execute arbitrary code on the victim's machine. This research project studies how web applications use the features provided by web browsers and how user systems can be protected by restricting unnecessary browser features.This project addresses web browser security by reducing the browser feature footprint, thereby reducing the browser attack surface and mitigating many classes of attacks. The researchers are building a feature-instrumented browser that reports what functionality is used by a web application. Then, they leverage that information to automatically identify when web applications diverge from their expected behavior and attack the user's browser. To enable users to use the most up-to-date browsers, while protecting them from unnecessary and risky browser features, the research team is building a system to decouple features from the browser.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Next Generation Black-Box Web Application Vulnerability Analysis
  • 批准号:
    1651661
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $41.66万
  • 财政年份:
    2017
  • 负责人:
    Adam Doupe
  • 依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
  • 批准号:
    1623269
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.46万
  • 财政年份:
    2016
  • 负责人:
    Adam Doupe
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: