DocumentCode :
1727495
Title :
Resolving JavaScript Vulnerabilities in the Browser Runtime
Author :
Ofuonye, Ejike ; Miller, James
Author_Institution :
ECE Dept., Univ. of Alberta, Edmonton, AB
fYear :
2008
Firstpage :
57
Lastpage :
66
Abstract :
The volume of Web based malware on the Internet keeps rising despite huge investments on Web security. JavaScript, the dominant scripting language for Web applications, is the primary channel for most of these attacks. In this paper, we describe research into the design and implementation of new Web client protection system based on code instrumentation techniques. This system combines traditional static analysis techniques with a dynamic HTML, CSS and JavaScript code runtime monitoring agent to offer an efficient, easily deployable, policy driven framework for improved user protection. Rewriting and runtime monitoring are based on providing safe equivalents of JavaScript code constructs known to contain in securities and hence exploitable by malicious Web applications. As a demonstration of the practical capabilities of our framework, we also include a case study attack and empirical analysis of some of its various aspects across 1000 home pages belonging to the most popular web sites on the Internet.
Keywords :
Internet; Java; hypermedia markup languages; rewriting systems; security of data; system monitoring; Internet; JavaScript code runtime monitoring agent; JavaScript vulnerability; Web client protection system; Web security; browser runtime; cascaded style sheet; code instrumentation technique; dynamic HTML; scripting language; static analysis technique; Cascading style sheets; HTML; Instruments; Internet; Investments; Java; Monitoring; Protection; Runtime; Security; Browser security; JavaScript Instrumentation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Reliability Engineering, 2008. ISSRE 2008. 19th International Symposium on
Conference_Location :
Seattle, WA
ISSN :
1071-9458
Print_ISBN :
978-0-7695-3405-3
Electronic_ISBN :
1071-9458
Type :
conf
DOI :
10.1109/ISSRE.2008.11
Filename :
4700310
Link To Document :
بازگشت