TC: Medium: Securing JavaScript Web Applications via Staged Policy Enforcement
TC: Medium: Securing JavaScript Web Applications via Staged Policy Enforcement
批准号:
0964702
负责人:
Ranjit Jhala
金额:
$115.19万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-04-01 至 2015-03-31
中文摘要
JavaScript是现代互联网计算的通用语言。与传统代码不同,JavaScript具有高度的动态性和延展性。虽然JavaScript越来越多地用于处理银行信息和社会保险号等敏感信息的安全关键应用程序,但Web浏览器针对JavaScript的沙箱机制(“同源策略”)过于粗糙,无法充分保护在运行时从相互不信任的来源组合代码的“mashhups”。该项目提供了一些工具,通过执行由开发人员和用户编写的安全策略来保护JavaScript应用程序免受错误或恶意代码的侵害,这些策略指定了应该信任的代码和必须保护的数据。面对像mashup这样的动态应用程序,传统的强制机制要么要求进行一次不完整的初始分析,要么要求在添加代码时从头开始进行昂贵的重新分析。这个项目引入了分阶段的程序分析。在每个阶段,在已知代码的情况下,执行尽可能多的分析;分析计算的其余部分被推迟,直到有更多的代码可用。该系统在浏览器中实现,并在真实的网站上进行评估,必须具有足够的可扩展性,以便与复杂的流行网站一起使用;精确到足以产生很少的误报;足够高效,在终端用户的浏览器上运行,没有明显的性能下降;用户友好的最大限度地减少了用户的干预,并提供了受保护站点的忠实再现。对于用户来说,该项目将使Web 2.0应用程序更安全、更可靠,而不会降低浏览体验。对于开发人员来说,它将为动态Web 2.0应用程序提供早期错误检测和安全执行的保证。
英文摘要
JavaScript is the lingua franca of modern Internet computing. Unlike traditional code, JavaScript is highly dynamic and malleable. While JavaScript is increasingly used in security-critical applications that manipulate sensitive information like banking information and social security numbers, Web browsers' sandboxing mechanism for JavaScript (the "same-origin policy") is too coarse to adequately secure "mashups" that combine code at runtime from mutually distrusting origins.This project provides tools to secure JavaScript applications from buggy or malicious code by enforcing security policies, written by developers and users, that specify what code should be trusted and what data must be protected.Faced with dynamic applications like mashups, traditional enforcement mechanisms call for either one incomplete initial analysis or expensive from-scratch re-analysis whenever code is added. This project instead introduces staged program analysis. At each stage, as much analysis as possible is performed as possible given the known code; the remainder of the analysis computation is deferred until more code becomes available.The system, implemented in a browser and evaluated on real Web sites, must be scalable enough to use with complex, popular sites; precise enough to produce few false positives; efficient enough to run on end users' browsers without noticeable performance degradation; and user-friendly in minimizing user intervention and providing a faithful rendition of protected sites.For users, the project will make Web 2.0 applications safer and more reliable, without degrading the browsing experience. For developers, it will provide early error detection and the guarantee of safe execution for dynamic Web 2.0 applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SHF: Small: Collaborative research: Language-Integrated Verification for Determininistic Parallelism
-
批准号:1911213
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2019
-
负责人:Ranjit Jhala
-
依托单位:
FMitF: Track II: Refinement Types in the Haskell Ecosystem
-
批准号:1917854
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2019
-
负责人:Ranjit Jhala
-
依托单位:
SHF: Medium: Collaborative Research: Program Analytics: Using Trace Data for Localization, Explanation and Synthesis
-
批准号:1763814
-
项目类别:Continuing Grant
-
资助金额:$90.0万
-
财政年份:2018
-
负责人:Ranjit Jhala
-
依托单位:
TWC: Medium: Detection and Prevention of Data Timing Channels
-
批准号:1514435
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2015
-
负责人:Ranjit Jhala
-
依托单位:
SHF: Small: Refinement Types For Verified Web Frameworks and Applications
-
批准号:1422471
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Ranjit Jhala
-
依托单位:
WORKSHOP: Future Directions For Formal Methods
-
批准号:1242686
-
项目类别:Standard Grant
-
资助金额:$8.47万
-
财政年份:2012
-
负责人:Ranjit Jhala
-
依托单位:
TWC: Small: New Foundations for Secure JavaScript
-
批准号:1223850
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2012
-
负责人:Ranjit Jhala
-
依托单位:
SHF: Small: Next-Generation, Dependent Type-based Software Model Checking for C
-
批准号:1218344
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2012
-
负责人:Ranjit Jhala
-
依托单位:
CSR-PDOS: A Structured Development Environment for Building Robust, Higher Performance Distributed Services
-
批准号:0720802
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Ranjit Jhala
-
依托单位:
CAREER: Software Reliability via Assert-Generated Interfaces
-
批准号:0644361
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Ranjit Jhala
-
依托单位:
Collaborative: Software Verification for Hardware Models
-
批准号:0702603
-
项目类别:Standard Grant
-
资助金额:$24.0万
-
财政年份:2007
-
负责人:Ranjit Jhala
-
依托单位:
海外基金