ESCUDO: A Fine-grained Protection Model for Web Browsers

被引:14
|
作者
Jayaraman, Karthick [1 ]
Du, Wenliang [1 ]
Rajagopalan, Balamurugan [1 ]
Chapin, Steve J. [1 ]
机构
[1] Syracuse Univ, Dept EECS, Syracuse, NY 13244 USA
来源
2010 INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS ICDCS 2010 | 2010年
关键词
D O I
10.1109/ICDCS.2010.71
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are no longer simple hyperlinked documents. They have progressively evolved to become highly complex-web pages combine content from several sources (with varying levels of trustworthiness), and incorporate significant portions of client-side code. However, the prevailing web protection model, the same-origin policy, has not adequately evolved to manage the security consequences of this additional complexity. As a result, web applications have become attractive targets of exploitation. We argue that this disconnection between the protection needs of modern web applications and the protection models used by web browsers that manage those applications amounts to a failure of access control. In this paper, we present ESCUDO, a new web browser protection model designed based on established principles of mandatory access control. We describe our implementation of a prototype of ESCUDO in the Lobo web browser, and illustrate how web applications can use ESCUDO for securing their resources. Our evaluation results indicate that ESCUDO incurs low overhead. To support backwards compatibility, ESCUDO defaults to the same-origin policy for legacy applications.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] POSTER: DIEGO: A Fine-Grained Access Control for Web Browsers
    Javed, Ashar
    PROCEEDINGS OF THE 18TH ACM CONFERENCE ON COMPUTER & COMMUNICATIONS SECURITY (CCS 11), 2011, : 789 - 791
  • [2] WebPol: Fine-Grained Information Flow Policies for Web Browsers
    Bichhawat, Abhishek
    Rajani, Vineet
    Jain, Jinank
    Garg, Deepak
    Hammer, Christian
    COMPUTER SECURITY - ESORICS 2017, PT I, 2018, 10492 : 242 - 259
  • [3] On the Feasibility of Fine-Grained TLS Security Configurations in Web Browsers Based on the Requested Domain Name
    Alashwali, Eman Salem
    Rasmussen, Kasper
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT II, 2018, 255 : 213 - 228
  • [4] A fine-grained access control model for Web services
    Bertino, E
    Squicciarini, AC
    Mevi, D
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 33 - 40
  • [5] Fine-Grained Data-Centric Content Protection Policy for Web Applications
    Wang, Zilun
    Meng, Wei
    Lyu, Michael R.
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 2845 - 2859
  • [6] Fine-grained Service Side Access Control Model for Web Application
    Liang, Zhijun
    Zhang, Hua
    Zhao, Zhonghua
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON INFORMATION SCIENCES, MACHINERY, MATERIALS AND ENERGY (ICISMME 2015), 2015, 126 : 1 - 6
  • [7] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [8] Fine-Grained Crowdsourcing for Fine-Grained Recognition
    Jia Deng
    Krause, Jonathan
    Li Fei-Fei
    2013 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2013, : 580 - 587
  • [9] Authentic attributes with fine-grained anonymity protection
    Stubblebine, SG
    Syverson, PF
    FINANCIAL CRYPTOGRAPHY, PROCEEDINGS, 2001, 1962 : 276 - 294
  • [10] CACL - EFFICIENT FINE-GRAINED PROTECTION FOR OBJECTS
    RICHARDSON, J
    SCHWARZ, P
    CABRERA, LF
    SIGPLAN NOTICES, 1992, 27 (10): : 263 - 275