Object capabilities and isolation of untrusted web applications

77Citations
Citations of this article
84Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A growing number of current web sites combine active content (applications) from untrusted sources, as in so-called mashups. The object-capability model provides an appealing approach for isolating untrusted content: if separate applications are provided disjoint capabilities, a sound objectcapability framework should prevent untrusted applications from interfering with each other, without preventing interaction with the user or the hosting page. In developing language-based foundations for isolation proofs based on object-capability concepts, we identify a more general notion of authority safety that also implies resource isolation. After proving that capability safety implies authority safety, we show the applicability of our framework for a specific class of mashups. In addition to proving that a JavaScript subset based on Google Caja is capability safe, we prove that a more expressive subset of JavaScript is authority safe, even though it is not based on the object-capability model. © 2010 IEEE.

Cite

CITATION STYLE

APA

Maffeis, S., Mitchell, J. C., & Taly, A. (2010). Object capabilities and isolation of untrusted web applications. In Proceedings - IEEE Symposium on Security and Privacy (pp. 125–140). https://doi.org/10.1109/SP.2010.16

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free