首页> 外文期刊>Journal of Logic and Algebraic Programming >Survey on JavaScript security policies and their enforcement mechanisms in a web browser
【24h】

Survey on JavaScript security policies and their enforcement mechanisms in a web browser

机译:Web浏览器中JavaScript安全策略及其执行机制的调查

获取原文
获取原文并翻译 | 示例

摘要

We observe a rapid growth of web-based applications every day. These applications are executed in the web browser, where they interact with a variety of information belonging to the user. The dynamism of web applications is provided by the use of web scripts, and in particular JavaScript, that accesses this information through a browser-provided set of APIs. Unfortunately, some of the scripts use the given functionality in malicious ways. Over the last decade, a substantial number of web-based attacks that violate user's privacy and security have been detected. For this reason, web script security has been an active area of research. Both computer security researchers and web developers have proposed a number of techniques to enforce different security and privacy policies in the web browser. Among all the works on web browser security, we survey dynamic techniques based on runtime monitoring as well as secure information flow techniques. We then combine and compare the security and privacy policies they enforce, and the way the enforcement is done. We target two groups of readers: 1) for computer security researchers we propose an overview of security-relevant components of the web browser and the security policies based on these components, we also show how well-known enforcement techniques are applied in a web browser setting; 2) for web developers we propose a classification of security policies, comparison of existing enforcement mechanisms proposed in the literature and explanation of formal guarantees that they provide.
机译:我们观察到基于Web的应用程序每天都在快速增长。这些应用程序是在Web浏览器中执行的,它们在其中与属于用户的各种信息进行交互。 Web应用程序的动态性是通过使用Web脚本(尤其是JavaScript)来提供的,该脚本通过浏览器提供的API集访问此信息。不幸的是,某些脚本以恶意方式使用了给定的功能。在过去的十年中,已经检测到大量基于Web的攻击,这些攻击侵犯了用户的隐私和安全性。因此,Web脚本安全性一直是研究的活跃领域。计算机安全研究人员和Web开发人员都提出了许多技术,以在Web浏览器中实施不同的安全和隐私策略。在有关Web浏览器安全性的所有作品中,我们调查了基于运行时监视的动态技术以及安全的信息流技术。然后,我们结合并比较它们执行的安全和隐私策略以及执行的方式。我们针对两组读者:1)针对计算机安全研究人员,我们对Web浏览器中与安全相关的组件和基于这些组件的安全策略进行了概述,并且还展示了如何在Web浏览器中应用众所周知的实施技术。设置; 2)对于Web开发人员,我们建议对安全策略进行分类,比较文献中提出的现有执行机制,并解释其提供的正式保证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号