메뉴 건너뛰기




Volumn , Issue , 2011, Pages 307-316

WebJail: Least-privilege integration of third-party components in web mashups

Author keywords

Least privilege integration; Sandbox; Web application security; Web mashups

Indexed keywords

FACEBOOK; FIREFOX; HIGH LEVEL POLICIES; INDIVIDUAL COMPONENTS; INTEGRATION TECHNIQUES; INTERNET USERS; JAVASCRIPT; LEAST-PRIVILEGE INTEGRATION; MASHUPS; MICROBENCHMARKS; MOZILLA; PERFORMANCE PENALTIES; POLICY LANGUAGE; SAME-ORIGIN POLICY; SANDBOX; SECURITY ARCHITECTURE; WEB 2.0; WEB APPLICATION; WEB APPLICATION SECURITY;

EID: 84855708536     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2076732.2076775     Document Type: Conference Paper
Times cited : (50)

References (34)
  • 1
    • 67449088776 scopus 로고    scopus 로고
    • Securing frame communication in browsers
    • June
    • A. Barth, C. Jackson, and J. C. Mitchell. Securing frame communication in browsers. Commun. ACM, 52:83-91, June 2009.
    • (2009) Commun. ACM , vol.52 , pp. 83-91
    • Barth, A.1    Jackson, C.2    Mitchell, J.C.3
  • 5
    • 77949443194 scopus 로고    scopus 로고
    • Csfire: Transparent client-side mitigation of malicious cross-domain requests
    • Springer Berlin / Heidelberg, February
    • P. De Ryck, L. Desmet, T. Heyman, F. Piessens, and W. Joosen. Csfire: Transparent client-side mitigation of malicious cross-domain requests. In Lecture Notes in Computer Science, volume 5965, pages 18-34. Springer Berlin / Heidelberg, February 2010.
    • (2010) Lecture Notes in Computer Science , vol.5965 , pp. 18-34
    • De Ryck, P.1    Desmet, L.2    Heyman, T.3    Piessens, F.4    Joosen, W.5
  • 6
    • 80053028570 scopus 로고    scopus 로고
    • Automatic and precise client-side protection against csrf attacks
    • V. Atluri and C. Diaz, editors, Computer Security - ESORICS 2011. Springer Berlin / Heidelberg
    • P. De Ryck, L. Desmet, W. Joosen, and F. Piessens. Automatic and precise client-side protection against csrf attacks. In V. Atluri and C. Diaz, editors, Computer Security - ESORICS 2011, volume 6879 of Lecture Notes in Computer Science, pages 100-116. Springer Berlin / Heidelberg, 2011.
    • (2011) Lecture Notes in Computer Science , vol.6879 , pp. 100-116
    • De Ryck, P.1    Desmet, L.2    Joosen, W.3    Piessens, F.4
  • 11
    • 84855661932 scopus 로고    scopus 로고
    • Google. Google Latitude. https://www.google.com/latitude/.
  • 12
    • 84890883068 scopus 로고    scopus 로고
    • Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code
    • Aug
    • S. Guarnieri and B. Livshits. Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code. In Proceedings of the Usenix Security Symposium, Aug. 2009.
    • (2009) Proceedings of the Usenix Security Symposium
    • Guarnieri, S.1    Livshits, B.2
  • 14
    • 84855700024 scopus 로고    scopus 로고
    • Involver
    • Involver. Tweets To Pages. http://www.facebook.com/TweetsApp.
  • 15
    • 84855661935 scopus 로고    scopus 로고
    • Jacaranda
    • Jacaranda. Jacaranda. http://jacaranda.org.
  • 16
    • 35348860223 scopus 로고    scopus 로고
    • Defeating script injection attacks with browser-enforced embedded policies
    • DOI 10.1145/1242572.1242654, 16th International World Wide Web Conference, WWW2007
    • T. Jim, N. Swamy, and M. Hicks. Defeating Script Injection Attacks with Browser-Enforced Embedded Policies. In WWW '07: Proceedings of the 16th international conference on World Wide Web, pages 601-610, New York, NY, USA, 2007. ACM. (Pubitemid 47582289)
    • (2007) 16th International World Wide Web Conference, WWW2007 , pp. 601-610
    • Jim, T.1    Swamy, N.2    Hicks, M.3
  • 20
    • 84855675152 scopus 로고    scopus 로고
    • G. Maone. Noscript 2.0.9.9. http://noscript.net/, 2011.
    • (2011)
    • Maone, G.1
  • 21
    • 77955186827 scopus 로고    scopus 로고
    • ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser
    • May
    • L. Meyerovich and B. Livshits. ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser. In IEEE Symposium on Security and Privacy, May 2010.
    • (2010) IEEE Symposium on Security and Privacy
    • Meyerovich, L.1    Livshits, B.2
  • 27
    • 84855661941 scopus 로고    scopus 로고
    • J. Ruderman. Configurable Security Policies. http://www.mozilla.org/ projects/security/components/ConfigPolicy.html.
    • Ruderman, J.1
  • 28
    • 84855655942 scopus 로고    scopus 로고
    • J. Samuel. Requestpolicy 0.5.20. http://www.requestpolicy.com, 2011.
    • (2011)
    • Samuel, J.1
  • 30
    • 84907402135 scopus 로고    scopus 로고
    • Adjail: Practical enforcement of confidentiality and integrity policies on web advertisements
    • Aug
    • M. Ter Louw, K. T. Ganesh, and V. Venkatakrishnan. Adjail: Practical enforcement of confidentiality and integrity policies on web advertisements. In 19th USENIX Security Symposium, Aug. 2010.
    • (2010) 19th USENIX Security Symposium
    • Ter Louw, M.1    Ganesh, K.T.2    Venkatakrishnan, V.3
  • 31
    • 84855661938 scopus 로고    scopus 로고
    • The FaceBook Team. FBJS. http://wiki.developers.facebook.com/index.php/ FBJS.
  • 32
    • 84855655939 scopus 로고    scopus 로고
    • W3C. W3C Standards and drafts - Javascript APIs. http://www.w3.org/TR/ #tr-Javascript-APIs.
  • 33
    • 84855700027 scopus 로고    scopus 로고
    • Willem De Groef. ConScript For Firefox. http://cqrit.be/conscript/.
    • De Groef, W.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.