首页> 外文会议>2016 IEEE Cybersecurity Development >Enforcing Content Security by Default within Web Browsers
【24h】

Enforcing Content Security by Default within Web Browsers

机译:默认情况下,在Web浏览器中实施内容安全性

获取原文
获取原文并翻译 | 示例

摘要

Web browsers were initially designed to retrieve resources on the world wide web in a static manner such that adding security checks in select locations throughout the codebase sufficiently provided the necessary security guarantees of the web. Even though systematic security checks were always performed, those security checks were sprinkled throughout the codebase. Over time, various specifications for dynamically loading content have proven that such a scattered security model is error-prone. Instead of opting into security checks wherever resource loads are initiated throughout the codebase, we present an approach where security checks are performed by default. By equipping every resource load with a loading context (which includes information about who initiated the load, the load type, etc.), our approach enforces an opt-out security mechanism performing security checks by default by consulting a centralized security manager. In addition, the added load context allows to provide the same security guarantees for resource loads which encounter a server-side redirect.
机译:最初设计Web浏览器是为了以静态方式检索万维网上的资源,以便在整个代码库中的选定位置中添加安全检查,足以为Web提供必要的安全保证。即使始终执行系统的安全检查,这些安全检查仍散布在整个代码库中。随着时间的流逝,用于动态加载内容的各种规范已证明这种分散的安全模型容易出错。我们提供了一种默认情况下执行安全检查的方法,而不是选择在整个代码库中启动资源加载的任何地方进行安全检查。通过为每个资源负载配备负载上下文(包括有关谁发起负载,负载类型等信息),我们的方法通过咨询中央安全经理来强制执行默认情况下执行安全检查的退出安全机制。另外,增加的负载上下文允许为遇到服务器端重定向的资源负载提供相同的安全保证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号