• DocumentCode
    1807221
  • Title

    A safety-oriented platform for Web applications

  • Author

    Cox, Richard S. ; Hansen, Jacob Gorm ; Gribble, Steven D. ; Levy, Henry M.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Washington Univ.
  • fYear
    2006
  • fDate
    21-24 May 2006
  • Lastpage
    364
  • Abstract
    This paper describes the architecture and implementation of the Tahoma Web browsing system. Key to Tahoma is the browser operating system (BOS), a new trusted software layer on which Web browsers execute. The benefits of this architecture are threefold. First, the BOS runs the client-side component of each Web application (e.g., on-line banking, Web mail) in its own virtual machine. This provides strong isolation between Web services and the user´s local resources. Second, Tahoma lets Web publishers limit the scope of their Web applications by specifying which URLs and other resources their browsers are allowed to access. This limits the harm that can be caused by a compromised browser. Third, Tahoma treats Web applications as first-class objects that users explicitly install and manage, giving them explicit knowledge about and control over downloaded content and code. We have implemented a prototype of Tahoma using Linux and the Xen virtual machine monitor. Our security evaluation shows that Tahoma can prevent or contain 87% of the vulnerabilities that have been identified in the widely used Mozilla browser. In addition, our measurements of latency, throughput, and responsiveness demonstrate that users need not sacrifice performance for the benefits of stronger isolation and safety
  • Keywords
    Internet; network operating systems; online front-ends; security of data; virtual machines; Linux; Mozilla browser; Tahoma Web browsing system; Web applications; Web browser; Web services; Xen virtual machine monitor; browser operating system; safety-oriented platform; security evaluation; trusted software layer; Application software; Banking; Computer architecture; Delay; Operating systems; Postal services; Service oriented architecture; Uniform resource locators; Virtual machining; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2006 IEEE Symposium on
  • Conference_Location
    Berkeley/Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2574-1
  • Type

    conf

  • DOI
    10.1109/SP.2006.4
  • Filename
    1624025