首页> 外文会议>IEEE Computer Security Foundations Symposium >Knowledge-Based Security of Dynamic Secrets for Reactive Programs
【24h】

Knowledge-Based Security of Dynamic Secrets for Reactive Programs

机译:基于知识的反应性程序动态秘密的安全性

获取原文

摘要

Scripts on webpages could steal sensitive user data. Much work has been done, both in modeling and implementation, to enforce information flow control (IFC) of webpages to mitigate such attacks. It is common to model scripts running in an IFC mechanism as a reactive program. However, this model does not account for dynamic script behavior such as user action simulation, new DOM element generation, or new event handler registration, which could leak information. In this paper, we investigate how to secure sensitive user information, while maintaining the flexibility of declassification, even in the presence of active attackers-those who can perform the aforementioned actions. Our approach extends prior work on secure-multi-execution with stateful declassification by treating script-generated content specially to ensure that declassification policies cannot be manipulated by them. We use a knowledge-based progress-insensitive definition of security and prove that our enforcement mechanism is sound. We further prove that our enforcement mechanism is precise and has robust declassification (i.e. active attackers cannot learn more than their passive counterpart).
机译:网页上的脚本可能会窃取敏感的用户数据。在建模和实现方面,已经进行了大量工作来强制执行网页的信息流控制(IFC)以减轻此类攻击。通常,将以IFC机制运行的脚本建模为响应程序。但是,此模型未考虑动态脚本行为,例如用户操作模拟,新的DOM元素生成或新的事件处理程序注册,这些行为可能会泄漏信息。在本文中,我们研究了如何保护敏感的用户信息,同时保持解密的灵活性,即使在存在能够执行上述操作的主动攻击者的情况下也是如此。我们的方法通过特别处理脚本生成的内容以确保解密策略不能被它们操纵来扩展具有状态解密的安全多执行的先前工作。我们使用基于知识的对进度不敏感的安全性定义,并证明我们的执行机制是正确的。我们进一步证明了我们的执行机制是准确的,并且具有强大的解密能力(即主动攻击者不能比被动攻击者学到更多)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号