首页> 外文会议>International Conference on Information Security >CrowdFlow: Efficient Information Flow Security
【24h】

CrowdFlow: Efficient Information Flow Security

机译:CrowdFlow:高效的信息流安全性

获取原文

摘要

The widespread use of JavaScript (JS) as the dominant web programming language opens the door to attacks such as Cross Site Scripting that steal sensitive information from users. Information flow tracking successfully addresses current browser security shortcomings, but current implementations incur a significant runtime overhead cost that prevents adoption. We present a novel approach to information flow security that distributes the tracking workload across all page visitors by probabilistically switching between two JavaScript execution modes. Our framework reports attempts to steal information from a user's browser to a third party that maintains a blacklist of malicious URLs. Participating users can then benefit from receiving warnings about blacklisted URLs, similar to anti-phishing filters. Our measurements indicate that our approach is both efficient and effective. First, our technique is efficient because it reduces performance impact by an order of magnitude. Second, our system is effective, i.e., it detects 99.45% of all information flow violations on the Alexa Top 500 pages using a conservative 5 % sampling rate. Most sites need fewer samples in practice; and will therefore incur even less overhead.
机译:JavaScript(JS)作为主要的Web编程语言的广泛使用为诸如跨站点脚本攻击之类的攻击打开了大门,这些攻击从用户那里窃取了敏感信息。信息流跟踪可以成功解决当前浏览器的安全缺陷,但是当前的实现方式会导致运行时的开销很大,从而阻碍了采用。我们提出了一种新颖的信息流安全方法,该方法通过概率性地在两种JavaScript执行模式之间切换来在所有页面访问者之间分配跟踪工作量。我们的框架报告试图从用户的浏览器中窃取信息,并将其盗取给维护恶意URL黑名单的第三方。然后,与反网络钓鱼过滤器类似,参与用户可以从收到有关列入黑名单的URL的警告中受益。我们的测量表明,我们的方法既有效又有效。首先,我们的技术是有效的,因为它可以将性能影响降低一个数量级。其次,我们的系统是有效的,即它以5%的保守采样率检测到Alexa Top 500页面上所有信息流违规的99.45%。实际上,大多数站点需要的样本较少;因此将产生更少的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号