首页> 外文会议>ACM symposium on access control models and technologies >An Architecture for Enforcing End-to-End Access Control Over Web Applications
【24h】

An Architecture for Enforcing End-to-End Access Control Over Web Applications

机译:用于对Web应用程序执行端到端访问控制的架构

获取原文

摘要

The web is now being used as a general platform for hosting distributed applications like wikis, bulletin board messaging systems and collaborative editing environments. Data from multiple applications originating at multiple sources all intermix in a single web browser, making sensitive data stored in the browser subject to a broad milieu of attacks (cross-site scripting, cross-site request forgery and others). The fundamental problem is that existing web infrastructure provides no means for enforcing end-to-end security on data. To solve this we design an architecture using mandatory access control (MAC) enforcement. We overcome the limitations of traditional MAC systems, implemented solely at the operating system layer, by unifying MAC enforcement across virtual machine, operating system, networking and application layers. We implement our architecture using Xen virtual machine management, SELinux at the operating system layer, labeled IPsec for networking and our own label-enforcing web browser, called FlowwolF. We tested our implementation and find that it performs well, supporting data intermixing while still providing end-to-end security guarantees.
机译:现在,网络被用作托管Wiki,Bulletin Lobs Messaging Systems和协作编辑环境等分布式应用程序的一般平台。来自多个应用程序的多个应用程序的数据在单个Web浏览器中的所有Intermix中,使存储在浏览器中的敏感数据受到广泛的攻击(跨站点脚本,跨站点请求伪造等)。基本问题是现有的Web Infrastructure提供对执行数据的端到端安全性的方法没有提供手段。要解决此问题,我们使用强制访问控制(Mac)实施来设计架构。我们通过跨虚拟机,操作系统,网络和应用程序层统一MAC强制来克服传统MAC系统的局限性,仅在操作系统层。我们使用Xen Virtual Machiness Management实现我们的架构,操作系统层中的SELinux,标有IPSec,用于网络和我们自己的标签强制Web浏览器,名为Flowwolf。我们测试了我们的实现,发现它表现良好,支持数据混合,同时仍提供端到端的安全保证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号