메뉴 건너뛰기




Volumn , Issue , 2012, Pages 1-10

JSand: Complete client-side sandboxing of third-party JavaScript without browser modifications

Author keywords

Sandbox; Script Inclusion; Security Architecture; Web Application Security; Web Mashups

Indexed keywords

DIFFERENT ORIGINS; JAVASCRIPT; MASHUPS; SANDBOX; SANDBOXING; SECURITY ARCHITECTURE; WEB APPLICATION SECURITY;

EID: 84872105489     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2420950.2420952     Document Type: Conference Paper
Times cited : (85)

References (41)
  • 2
    • 84954091773 scopus 로고    scopus 로고
    • BuiltWith. jQuery Usage Statistics. http://trends.builtwith.com/ javascript/jQuery.
    • JQuery Usage Statistics
  • 5
  • 7
    • 77955223614 scopus 로고    scopus 로고
    • Noninterference through secure multi-execution
    • IEEE, Washington, DC, USA
    • D. Devriese and F. Piessens. Noninterference through secure multi-execution. In Proc of SP'10, IEEE, pages 109-124, Washington, DC, USA, 2010.
    • (2010) Proc of SP'10 , pp. 109-124
    • Devriese, D.1    Piessens, F.2
  • 9
    • 84872120755 scopus 로고    scopus 로고
    • Jacaranda. Jacaranda. http://jacaranda.org.
    • Jacaranda
  • 10
    • 35348860223 scopus 로고    scopus 로고
    • Defeating script injection attacks with browser-enforced embedded policies
    • DOI 10.1145/1242572.1242654, 16th International World Wide Web Conference, WWW2007
    • T. Jim, N. Swamy, and M. Hicks. Defeating Script Injection Attacks with Browser-Enforced Embedded Policies. In Proc. of WWW'07, pages 601-610, New York, NY, USA, 2007. ACM. (Pubitemid 47582289)
    • (2007) 16th International World Wide Web Conference, WWW2007 , pp. 601-610
    • Jim, T.1    Swamy, N.2    Hicks, M.3
  • 13
    • 85037344573 scopus 로고    scopus 로고
    • Contego: Capability-based access control for web browsers
    • Berlin, Heidelberg. Springer-Verlag
    • T. Luo and W. Du. Contego: capability-based access control for web browsers. TRUST'11, pages 231-238, Berlin, Heidelberg, 2011. Springer-Verlag.
    • (2011) TRUST'11 , pp. 231-238
    • Luo, T.1    Du, W.2
  • 14
    • 77955217182 scopus 로고    scopus 로고
    • Object capabilities and isolation of untrusted web applications
    • IEEE
    • S. Maffeis, J. Mitchell, and A. Taly. Object capabilities and isolation of untrusted web applications. In Proc. of SP'10. IEEE, 2010.
    • (2010) Proc. of SP'10
    • Maffeis, S.1    Mitchell, J.2    Taly, A.3
  • 15
    • 70350525212 scopus 로고    scopus 로고
    • Language-based isolation of untrusted Javascript
    • IEEE
    • S. Maffeis and A. Taly. Language-based isolation of untrusted Javascript. In Proc. of CSF'09, IEEE, 2009.
    • (2009) Proc. of CSF'09
    • Maffeis, S.1    Taly, A.2
  • 16
    • 84975280608 scopus 로고    scopus 로고
    • Safe wrappers and sane policies for self protecting JavaScript
    • J. Magazinius, P. Phung, and D. Sands. Safe wrappers and sane policies for self protecting JavaScript. In Proc. of Nordsec'10, 2010.
    • (2010) Proc. of Nordsec'10
    • Magazinius, J.1    Phung, P.2    Sands, D.3
  • 17
    • 84872104450 scopus 로고    scopus 로고
    • ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser
    • L. Meyerovich and B. Livshits. ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser. In Proc. of SP'10, 2010.
    • (2010) Proc. of SP'10
    • Meyerovich, L.1    Livshits, B.2
  • 18
    • 84872118720 scopus 로고    scopus 로고
    • Microsoft Live Labs
    • Microsoft Live Labs. Live Labs Websandbox. http://websandbox.org.
    • Live Labs Websandbox
  • 19
    • 84872105488 scopus 로고    scopus 로고
    • Mihai Bazon. UglifyJS. https://github.com/mishoo/UglifyJS/.
    • Bazon, M.1
  • 24
    • 84872117155 scopus 로고    scopus 로고
    • NoMoreSleep
    • NoMoreSleep. jquery-geolocation. http://code.google.com/p/jquery- geolocation/.
  • 25
    • 84864053697 scopus 로고    scopus 로고
    • A two-tier sandbox architecture for untrusted javascript
    • New York, NY, ACM
    • P. H. Phung and L. Desmet. A two-tier sandbox architecture for untrusted javascript. In Proc. of JSTools'12, pages 1-10, New York, NY, 2012. ACM.
    • (2012) Proc. of JSTools'12 , pp. 1-10
    • Phung, P.H.1    Desmet, L.2
  • 26
    • 77952327855 scopus 로고    scopus 로고
    • Lightweight self-protecting JavaScript
    • New York, NY, USA, ACM
    • P. H. Phung, D. Sands, and A. Chudnov. Lightweight self-protecting JavaScript. ASIACCS '09, pages 47-60, New York, NY, USA, 2009. ACM.
    • (2009) ASIACCS '09 , pp. 47-60
    • Phung, P.H.1    Sands, D.2    Chudnov, A.3
  • 29
    • 85076780225 scopus 로고    scopus 로고
    • BrowserShield: Vulnerability-driven filtering of dynamic HTML
    • Berkeley, CA, USA. USENIX Association
    • C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. BrowserShield: vulnerability-driven filtering of dynamic HTML. In Proc. of OSDI'06, pages 61-74, Berkeley, CA, USA, 2006. USENIX Association.
    • (2006) Proc. of OSDI'06 , pp. 61-74
    • Reis, C.1    Dunagan, J.2    Wang, H.J.3    Dubrovsky, O.4    Esmeir, S.5
  • 30
  • 31
    • 77954584716 scopus 로고    scopus 로고
    • Reining in the web with content security policy
    • New York, NY, ACM
    • S. Stamm, B. Sterne, and G. Markham. Reining in the web with content security policy. In Proc. of WWW'10, pages 921-930, New York, NY, 2010. ACM.
    • (2010) Proc. of WWW'10 , pp. 921-930
    • Stamm, S.1    Sterne, B.2    Markham, G.3
  • 32
    • 84907402135 scopus 로고    scopus 로고
    • AdJail: Practical enforcement of confidentiality and integrity policies on web advertisements
    • Aug.
    • M. Ter Louw, K. T. Ganesh, and V. Venkatakrishnan. AdJail: Practical Enforcement of Confidentiality and Integrity Policies on Web Advertisements. In 19th USENIX Security Symposium, Aug. 2010.
    • (2010) 19th USENIX Security Symposium
    • Ter Louw, M.1    Ganesh, K.T.2    Venkatakrishnan, V.3
  • 33
    • 84872110438 scopus 로고    scopus 로고
    • The FaceBook Team. FBJS. http: //wiki.developers.facebook.com/index.php/ FBJS.
    • FBJS
  • 34
    • 84855708536 scopus 로고    scopus 로고
    • WebJail: Least-privilege integration of third-party components in web mashups
    • New York, NY, USA, ACM
    • S. Van Acker, P. De Ryck, L. Desmet, F. Piessens, and W. Joosen. WebJail: least-privilege integration of third-party components in web mashups. ACSAC '11, pages 307-316, New York, NY, USA, 2011. ACM.
    • (2011) ACSAC '11 , pp. 307-316
    • Van Acker, S.1    De Ryck, P.2    Desmet, L.3    Piessens, F.4    Joosen, W.5
  • 35
    • 80053507303 scopus 로고    scopus 로고
    • Proxies: Design principles for robust object-oriented intercession APIs
    • Oct.
    • T. Van Cutsem and M. S. Miller. Proxies: design principles for robust object-oriented intercession APIs. SIGPLAN Not., 45(12):59-72, Oct. 2010.
    • (2010) SIGPLAN Not. , vol.45 , Issue.12 , pp. 59-72
    • Van Cutsem, T.1    Miller, M.S.2
  • 40
    • 84865647705 scopus 로고    scopus 로고
    • Characterizing insecure JavaScript practices on the web
    • April
    • C. Yue and H. Wang. Characterizing Insecure JavaScript Practices on the Web. In Proc. of WWW'09, pages 961-961, April 2009.
    • (2009) Proc. of WWW'09 , pp. 961-961
    • Yue, C.1    Wang, H.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.