首页> 外文会议>International Workshop on Formal Aspects of Security and Trust >Better Security and Privacy for Web Browsers: A Survey of Techniques, and a New Implementation
【24h】

Better Security and Privacy for Web Browsers: A Survey of Techniques, and a New Implementation

机译:更好的Web浏览器安全性和隐私:技术调查以及新的实施

获取原文

摘要

The web browser is one of the most security critical software components today. It is used to interact with a variety of important applications and services, including social networking services, e-mail services, and e-commerce and e-health applications. But the same browser is also used to visit less trustworthy sites, and it is unreasonable to make it the end-user's responsibility to "browse safely". So it is an important design goal for a browser to provide adequate privacy and security guarantees, and to make sure that potentially malicious content from one web site can not compromise the browser, violate the user's privacy, or interfere with other web sites that the user interacts with. Hence, browser security has been a very active topic of research over the past decade, and many proposals have been made for new browser security techniques or architectures. In the first part of this paper, we provide a survey of some important problems and some proposed solutions. We start with a very broad view on browser security problems, and then zoom in on the issues related to the security of JavaScript scripts on the Web. We discuss three important classes of techniques: fine-grained script access control, capability-secure scripting and information flow security for scripts, focusing on techniques with a solid formal foundation. In the second part of the paper, we describe a novel implementation of one information flow security technique. We discuss how we have implemented the technique of secure multi-execution in the Mozilla Firefox browser, and we report on some preliminary experiments with this implementation.
机译:Web浏览器是今天最安全的关键软件组件之一。它用于与各种重要的应用和服务进行互动,包括社交网络服务,电子邮件服务和电子商务和电子健康应用。但是相同的浏览器也用于访问较少值得信赖的网站,并且使其最终用户责任“安全”是不合理的。因此,浏览器提供足够的隐私和安全保障是一个重要的设计目标,并确保从一个网站的可能性恶意内容无法损害浏览器,违反用户的隐私,或者干扰用户的其他网站与之互动。因此,在过去十年中,浏览器安全性是一项非常活跃的研究主题,已经为新的浏览器安全技术或架构进行了许多建议。在本文的第一部分,我们提供了对一些重要问题和一些提出的解决方案的调查。我们从浏览器安全问题开始非常广泛,然后放大与Web上的JavaScript脚本的安全性有关的问题。我们讨论了三种重要的技术类:细粒度脚本访问控制,能力 - 安全脚本和脚本信息流安全,专注于具有稳固正式基础的技术。在本文的第二部分中,我们描述了一种信息流安全技术的新颖实现。我们讨论如何在Mozilla Firefox浏览器中实现安全多执行的技术,我们报告了该实施的一些初步实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号