2011 · 53 citations · 27 references
EngineeringInformation SecuritySoftware EngineeringSource Code AnalysisSoftware AnalysisWeb AnalyticsHardware SecurityInformation Flow AnalysisManagementImplicit FlowModern Web 2.0Computer ScienceInformation ManagementStatic Program AnalysisLanguage-based SecurityInformation FlowDynamic Web PageSoftware SecurityProgram AnalysisSoftware TestingFormal Methods
Modern Web 2.0 pages combine scripts from several sources into a single client-side JavaScript program with almost no isolation. In order to prevent attacks from an untrusted third-party script or cross-site scripting, tracking provenance of data is imperative. However, no browser offers this security mechanism. This work presents the first information flow control mechanism for full JavaScript. We track information flow dynamically as much as possible but rely on intra-procedural static analysis to capture implicit flow. Our analysis handles even the dreaded eval function soundly and incorporates flow based on JavaScript's prototype inheritance. We implemented our analysis in a production JavaScript engine and report both qualitative as well as quantitative evaluation results.
27
Security Policies and Security Models
Joseph A. Goguen, José Meseguer · 1982 · 2.1K citations
A lattice model of secure information flow
Dorothy E. Denning · Communications of the ACM · 1976 · 1.9K citations · Full text
Fred B. Schneider · ACM Transactions on Information and System Security · 2000 · 1.3K citations · Full text