首页> 外文会议>International conference on future data and security engineering >MyWebGuard: Toward a User-Oriented Tool for Security and Privacy Protection on the Web
【24h】

MyWebGuard: Toward a User-Oriented Tool for Security and Privacy Protection on the Web

机译:MyWebGuard:迈向面向用户的网络安全和隐私保护工具

获取原文

摘要

We introduce a novel approach to implementing a browser-based tool for web users to protect their privacy. We propose to monitor the behaviors of JavaScript code within a webpage, especially operations that can read data within a browser or can send data from a browser to outside. Our monitoring mechanism is to ensure that all potential information leakage channels are detected. The detected leakage is either automatically prevented by our context-aware policies or decided by the user if needed. Our method advances the conventional same-origin policy standard of the Web by enforcing different policies for each source of the code. Although we develop the tool as a browser extension, our approach is browser-agnostic as it is based on standard JavaScript. Also, our method stands from existing proposals in the industry and literature. In particular, it does not rely on network request interception and blocking mechanisms provided by browsers, which face various technical issues. We implement a proof-of-concept prototype and perform practical evaluations to demonstrate the effectiveness of our approach. Our experimental results evidence that the proposed method can detect and prevent data leakage channels not captured by the leading tools such as Ghostery and uBlock Origin. We show that our prototype is compatible with major browsers and popular real-world websites with promising runtime performance.
机译:我们介绍一种新颖的方法来为网络用户实现基于浏览器的工具,以保护他们的隐私。我们建议监视网页中JavaScript代码的行为,尤其是可以在浏览器中读取数据或可以将数据从浏览器发送到外部的操作。我们的监控机制是确保检测到所有潜在的信息泄漏渠道。检测到的泄漏可以通过我们的上下文感知策略自动阻止,也可以根据需要由用户决定。我们的方法通过对代码的每个源强制执行不同的策略,从而改进了Web的常规同源策略标准。尽管我们将该工具作为浏览器扩展进行了开发,但是由于它基于标准JavaScript,因此我们的方法与浏览器无关。同样,我们的方法与行业和文献中的现有建议相吻合。特别是,它不依赖于浏览器提供的网络请求拦截和阻止机制,这些机制面临各种技术问题。我们实施了概念验证原型,并进行了实际评估,以证明我们方法的有效性。我们的实验结果证明,该方法可以检测并防止Ghostery和uBlock Origin等领先工具无法捕获的数据泄漏通道。我们证明了我们的原型与主要的浏览器和流行的现实世界网站兼容,并具有良好的运行时性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号