메뉴 건너뛰기




Volumn , Issue , 2010, Pages 163-172

An architecture for enforcing end-to-end access control over web applications

Author keywords

Access control; Policy compliance; Xen security modules

Indexed keywords

ACCESS CONTROL POLICIES; APPLICATION LAYERS; COLLABORATIVE EDITING; CROSS SITE SCRIPTING; DISTRIBUTED APPLICATIONS; END-TO-END SECURITY; FUNDAMENTAL PROBLEM; MANDATORY ACCESS CONTROL; MESSAGING SYSTEM; MULTIPLE APPLICATIONS; MULTIPLE SOURCE; OPERATING SYSTEMS; SECURITY MODULES; SENSITIVE DATAS; VIRTUAL MACHINE MANAGEMENT; VIRTUAL MACHINES; WEB APPLICATION; WEB INFRASTRUCTURE;

EID: 77954942438     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1809842.1809870     Document Type: Conference Paper
Times cited : (25)

References (30)
  • 3
    • 77954899053 scopus 로고    scopus 로고
    • Robust defenses for cross-site request forgery
    • ACM
    • A. Barth, C. Jackson, and J. Mitchell. Robust defenses for cross-site request forgery. In CCS'08. ACM, 228.
    • CCS'08 , pp. 228
    • Barth, A.1    Jackson, C.2    Mitchell, J.3
  • 5
    • 77952394606 scopus 로고    scopus 로고
    • An analysis of browser domain-isolation bugs and a light-weight transparent defense mechanism
    • ACM
    • S. Chen, D. Ross, and Y.-M. Wang. An analysis of browser domain-isolation bugs and a light-weight transparent defense mechanism. In CCS'07. ACM, 2007.
    • (2007) CCS'07
    • Chen, S.1    Ross, D.2    Wang, Y.-M.3
  • 7
    • 33750248123 scopus 로고    scopus 로고
    • Building a mac-based security architecture for the xen open-source hypervisor
    • IEEE Computer Society
    • R. S. et al. Building a mac-based security architecture for the xen open-source hypervisor. In ACSAC'05, pages 276-285. IEEE Computer Society, 2005.
    • (2005) ACSAC'05 , pp. 276-285
    • S., R.1
  • 10
    • 48649108967 scopus 로고    scopus 로고
    • Channels: Runtime system infrastructure for security-typed languages
    • December
    • B. Hicks, T. Misiak, and P. McDaniel. Channels: Runtime system infrastructure for security-typed languages. In ACSAC, December 2007.
    • (2007) ACSAC
    • Hicks, B.1    Misiak, T.2    McDaniel, P.3
  • 12
    • 84856138620 scopus 로고    scopus 로고
    • Mashupos: Operating system abstractions for client mashups
    • J. Howell, C. Jackson, H. Wang, and X. Fan. Mashupos: Operating system abstractions for client mashups. In HotOS., 2007.
    • (2007) HotOS
    • Howell, J.1    Jackson, C.2    Wang, H.3    Fan, X.4
  • 13
    • 3042626763 scopus 로고    scopus 로고
    • A proposal and implementation of automatic detection/collection system for cross-site scripting vulnerability
    • IEEE
    • O. Ismail, M. Etoh, Y. Kadobayashi, and S. Yamaguchi. A proposal and implementation of automatic detection/collection system for cross-site scripting vulnerability. In AINA'04. IEEE.
    • AINA'04
    • Ismail, O.1    Etoh, M.2    Kadobayashi, Y.3    Yamaguchi, S.4
  • 15
    • 35348905576 scopus 로고    scopus 로고
    • Subspace: Secure cross-domain communication for web mashups
    • C. Jackson and H. Wang. Subspace: Secure cross-domain communication for web mashups. In WWW'07.
    • WWW'07
    • Jackson, C.1    Wang, H.2
  • 17
    • 77954931261 scopus 로고    scopus 로고
    • Defeating script injection attacks with browser-enforced embedded policies
    • New York, NY, USA. ACM
    • T. Jim, N. Swamy, and M. Hicks. Defeating script injection attacks with browser-enforced embedded policies. In WWW, New York, NY, USA. ACM.
    • WWW
    • Jim, T.1    Swamy, N.2    Hicks, M.3
  • 20
    • 77954904903 scopus 로고    scopus 로고
    • MyBB Group. MyBB. http://www.mybboard.net/.
    • MyBB
  • 27
    • 41149087693 scopus 로고    scopus 로고
    • Browsershield: Vulnerability-driven filtering of dynamic html
    • USENIX Association
    • C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. Browsershield: vulnerability-driven filtering of dynamic html. In OSDI. USENIX Association.
    • OSDI
    • Reis, C.1    Dunagan, J.2    Wang, H.J.3    Dubrovsky, O.4    Esmeir, S.5
  • 28
    • 34548253921 scopus 로고    scopus 로고
    • Javascript instrumentation for browser security
    • New York, NY, USA. ACM
    • D. Yu, A. Chander, N. Islam, and I. Serikov. Javascript instrumentation for browser security. In POPL'07, pages 237-249, New York, NY, USA. ACM.
    • POPL'07 , pp. 237-249
    • Yu, D.1    Chander, A.2    Islam, N.3    Serikov, I.4
  • 29
    • 60649094297 scopus 로고    scopus 로고
    • OMOS: A framework for secure communication in mashup applications
    • IEEE
    • S. Zarandioon, D. Yao, and V. Ganapathy. OMOS: A Framework for Secure Communication in Mashup Applications. In ACSAC'08. IEEE.
    • ACSAC'08
    • Zarandioon, S.1    Yao, D.2    Ganapathy, V.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.