首页> 外文期刊>Journal of computer security >Hails: Protecting data privacy in untrusted web applications
【24h】

Hails: Protecting data privacy in untrusted web applications

机译:冰雹:保护不受信任的Web应用程序中的数据隐私

获取原文
获取原文并翻译 | 示例

摘要

Many modern web-platforms are no longer written by a single entity, such as a company or individual, but consist of a trusted core that can be extended by untrusted third-party authors. Examples of this approach include Facebook, Yammer, and Salesforce. Unfortunately, users running third-party "apps" have little control over what the apps can do with their private data. Today's platforms offer only ad hoc constraints on app behavior, leaving users an unfortunate trade-off between convenience and privacy. A principled approach to code confinement could allow the integration of untrusted code while enforcing flexible, end-to-end policies on data access. This paper presents a new framework, Hails, for building web platforms, that adds mandatory access control and a declarative policy language to the familiar MVC architecture. We demonstrate the flexibility of Hails by building several platforms, including GitStar, a code-hosting website that enforces robust privacy policies on user data even while allowing untrusted apps to deliver extended features to users.
机译:许多现代的网络平台不再由单个实体(例如公司或个人)编写,而是由可以由不受信任的第三方作者扩展的受信任核心组成。这种方法的示例包括Facebook,Yammer和Salesforce。不幸的是,运行第三方“应用程序”的用户几乎无法控制应用程序如何处理其私有数据。当今的平台仅对应用程序行为提供临时约束,从而给用户带来了便利与隐私之间的不幸折衷。一种有原则的代码限制方法可以允许不可信代码的集成,同时在数据访问方面实施灵活的端到端策略。本文提出了一个用于构建Web平台的新框架Hails,该框架为熟悉的MVC体系结构添加了强制访问控制和声明性策略语言。我们通过构建多个平台来展示Hails的灵活性,其中包括GitStar,这是一个代码托管网站,即使允许不受信任的应用程序向用户提供扩展功能,该网站也可以对用户数据实施可靠的隐私策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号