Resolving JavaScript vulnerabilities in the browser runtime

6Citations
Citations of this article
22Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The volume of web based malware on the Internet keeps rising despite huge investments on web security. JavaScript, the dominant scripting language for web applications, is the primary channel for most of these attacks. In this paper, we describe research into the design and implementation of new web client protection system based on code instrumentation techniques. This system combines traditional static analysis techniques with a dynamic HTML, CSS and JavaScript code runtime monitoring agent to offer an efficient, easily deployable, policy driven framework for improved user protection. Rewriting and runtime monitoring are based on providing safe equivalents of JavaScript code constructs known to contain insecurities and hence exploitable by malicious web applications. As a demonstration of the practical capabilities of our framework, we also include a case study attack and empirical analysis of some of its various aspects across 1000 home pages belonging to the most popular web sites on the Internet. © 2008 IEEE.

Cite

CITATION STYLE

APA

Ofuonye, E., & Miller, J. (2008). Resolving JavaScript vulnerabilities in the browser runtime. In Proceedings - International Symposium on Software Reliability Engineering, ISSRE (pp. 57–66). https://doi.org/10.1109/ISSRE.2008.11

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free