首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Between Worlds: Securing Mixed JavaScript/ActionScript Multi-Party Web Content
【24h】

Between Worlds: Securing Mixed JavaScript/ActionScript Multi-Party Web Content

机译:世界之间:确保混合的JavaScript / ActionScript多方Web内容的安全

获取原文
获取原文并翻译 | 示例

摘要

Mixed Flash and JavaScript content has become increasingly prevalent; its purveyance of dynamic features unique to each platform has popularized it for myriad web development projects. Although Flash and JavaScript security has been examined extensively, the security of untrusted content that combines both has received considerably less attention. This article considers this fusion in detail, outlining several practical scenarios that threaten the security of web applications. The severity of these attacks warrants the development of new techniques that address the security of Flash-JavaScript content considered as a whole, in contrast to prior solutions that have examined Flash or JavaScript security individually. Toward this end, the article presents FlashJaX, a cross-platform solution that enforces fine-grained, history-based policies that span both Flash and JavaScript. Using in-lined reference monitoring, FlashJaX safely embeds untrusted JavaScript and Flash content in web pages without modifying browser clients or using special plug-ins. The architecture of FlashJaX, its design and implementation, and a detailed security analysis are exposited. Experiments with advertisements from popular ad networks demonstrate that FlashJaX is transparent to policy-compliant advertisement content, yet blocks many common attack vectors that exploit the fusion of these web platforms.
机译:Flash和JavaScript的混合内容已变得越来越普遍。它为每个平台提供的独特动态功能使之在众多Web开发项目中得到了普及。尽管已经广泛检查了Flash和JavaScript的安全性,但结合了两者的不受信任内容的安全性却受到了相当少的关注。本文详细考虑了这种融合,概述了几种威胁Web应用程序安全的实际方案。与以前单独检查Flash或JavaScript安全性的解决方案相比,这些攻击的严重性保证了新技术的开发,这些技术可以解决整个Flash-JavaScript内容的安全性。为此,本文介绍了FlashJaX,这是一个跨平台的解决方案,可实施跨越Flash和JavaScript的细粒度,基于历史的策略。使用内联的参考监视,FlashJaX可以在网页中安全地嵌入不受信任的JavaScript和Flash内容,而无需修改浏览器客户端或使用特殊的插件。阐述了FlashJaX的体系结构,其设计和实现以及详细的安全性分析。来自流行广告网络的广告实验表明,FlashJaX对符合策略的广告内容透明,但是阻止了许多利用这些Web平台融合的常见攻击媒介。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号