DocumentCode :
3435526
Title :
ESCUDO: A Fine-Grained Protection Model for Web Browsers
Author :
Jayaraman, Karthick ; Du, Wenliang ; Rajagopalan, Balamurugan ; Chapin, Steve J.
Author_Institution :
Dept. of EECS, Syracuse Univ., Syracuse, NY, USA
fYear :
2010
fDate :
21-25 June 2010
Firstpage :
231
Lastpage :
240
Abstract :
Web applications are no longer simple hyperlinked documents. They have progressively evolved to become highly complex-web pages combine content from several sources (with varying levels of trustworthiness), and incorporate significant portions of client-side code. However, the prevailing web protection model, the same-origin policy, has not adequately evolved to manage the security consequences of this additional complexity. As a result, web applications have become attractive targets of exploitation. We argue that this disconnection between the protection needs of modern web applications and the protection models used by web browsers that manage those applications amounts to a failure of access control. In this paper, we present Escudo, a new web browser protection model designed based on established principles of mandatory access control. We describe our implementation of a prototype of Escudo in the Lobo web browser, and illustrate how web applications can use Escudo for securing their resources. Our evaluation results indicate that Escudo incurs low overhead. To support backwards compatibility, Escudo defaults to the same-origin policy for legacy applications.
Keywords :
authorisation; data privacy; online front-ends; Escudo; Lobo Web browser; Web pages; access control; client-side code; protection model; same-origin policy; Access control; Advertising; Distributed computing; Forgery; Java; Permission; Protection; Prototypes; Security; Web pages; Access Control; Browser Security; Web security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems (ICDCS), 2010 IEEE 30th International Conference on
Conference_Location :
Genova
ISSN :
1063-6927
Print_ISBN :
978-1-4244-7261-1
Type :
conf
DOI :
10.1109/ICDCS.2010.71
Filename :
5541712
Link To Document :
بازگشت