Matches in SemOpenAlex for { <https://semopenalex.org/work/W1647103339> ?p ?o ?g. }
- W1647103339 abstract "A web browser works with data and scripts from different sources, and these sources are not all trusted equally by the user of the browser. This fact requires web browser designers to take special care in order to keep information secure within the browser: data from one source should not be stolen or corrupted by a script from another source. This aspect of web browser design is what we will call web script security. The effectiveness of security checks designed to enforce web script security must ultimately be judged in terms of their effect on the outwardly visible behavior of the browser. In light of this fact, this dissertation defines a policy for web script security to refer to a logical constraint on a browser's behavior, stated exclusively in terms of the aspects that are outwardly visible, either to the network or to the user. Such end-to-end policies are naturally appealing. However, there is a reason they are rarely used for real-world systems: it is usually very unclear how to write down precise, flexible security policies of this sort. Supposing that one could write down such policies for web script security, a second obstacle would then arise: the problem of drawing a precise connection between such end-to-end policies and the security mechanisms that one would actually implement in a browser. This dissertation demonstrates that such information security policies for web browsers can in fact be written down—precisely and without reference to security enforcement mechanisms implemented inside the browser. Moreover, the mechanisms for enforcing those policies can be designed and formally proved correct within mathematical models of web browsers that are detailed enough to capture the inherent complexities of the domain. This dissertation supports these claims by (1) introducing mathematical tools for stating and proving end-to-end information security properties for software systems that are driven by buffered, asynchronous I/O; (2) introducing a particular mathematical model of a web browser that is accompanied by a security policy for confidentiality and is equipped with security mechanisms intended to enforce the policy; and (3) offering a proof that the security mechanisms in the model do enforce the policy, a proof which has been mechanized and verified in the Coq proof assistant." @default.
- W1647103339 created "2016-06-24" @default.
- W1647103339 creator A5018162548 @default.
- W1647103339 creator A5085361253 @default.
- W1647103339 date "2012-01-01" @default.
- W1647103339 modified "2023-09-25" @default.
- W1647103339 title "Foundations of web script security" @default.
- W1647103339 cites W105715719 @default.
- W1647103339 cites W109233749 @default.
- W1647103339 cites W120333500 @default.
- W1647103339 cites W1222699389 @default.
- W1647103339 cites W1492437080 @default.
- W1647103339 cites W1510473343 @default.
- W1647103339 cites W1510692643 @default.
- W1647103339 cites W1511116625 @default.
- W1647103339 cites W1512206543 @default.
- W1647103339 cites W1513989276 @default.
- W1647103339 cites W1516018459 @default.
- W1647103339 cites W1520961854 @default.
- W1647103339 cites W1525928249 @default.
- W1647103339 cites W1526757679 @default.
- W1647103339 cites W153093637 @default.
- W1647103339 cites W1531439671 @default.
- W1647103339 cites W1543478129 @default.
- W1647103339 cites W1547778521 @default.
- W1647103339 cites W1554129301 @default.
- W1647103339 cites W1557847811 @default.
- W1647103339 cites W1558552339 @default.
- W1647103339 cites W1581993637 @default.
- W1647103339 cites W1584813884 @default.
- W1647103339 cites W1590828018 @default.
- W1647103339 cites W1675836294 @default.
- W1647103339 cites W167927161 @default.
- W1647103339 cites W1725973462 @default.
- W1647103339 cites W1739542898 @default.
- W1647103339 cites W1839269954 @default.
- W1647103339 cites W1920159904 @default.
- W1647103339 cites W1961998804 @default.
- W1647103339 cites W1976371754 @default.
- W1647103339 cites W1977247323 @default.
- W1647103339 cites W1977764760 @default.
- W1647103339 cites W1980800818 @default.
- W1647103339 cites W1985725561 @default.
- W1647103339 cites W1986242696 @default.
- W1647103339 cites W1986681115 @default.
- W1647103339 cites W1991895580 @default.
- W1647103339 cites W1993090666 @default.
- W1647103339 cites W1998180710 @default.
- W1647103339 cites W2007975752 @default.
- W1647103339 cites W2008332764 @default.
- W1647103339 cites W2014784851 @default.
- W1647103339 cites W2016604944 @default.
- W1647103339 cites W2019404692 @default.
- W1647103339 cites W202191487 @default.
- W1647103339 cites W2025874281 @default.
- W1647103339 cites W2027146564 @default.
- W1647103339 cites W2027822753 @default.
- W1647103339 cites W2036910349 @default.
- W1647103339 cites W2037671236 @default.
- W1647103339 cites W2053739444 @default.
- W1647103339 cites W2054014134 @default.
- W1647103339 cites W2060857434 @default.
- W1647103339 cites W2061056245 @default.
- W1647103339 cites W2066195326 @default.
- W1647103339 cites W2072978486 @default.
- W1647103339 cites W2074877666 @default.
- W1647103339 cites W2080914957 @default.
- W1647103339 cites W2083940415 @default.
- W1647103339 cites W2090184259 @default.
- W1647103339 cites W2094873755 @default.
- W1647103339 cites W2095762545 @default.
- W1647103339 cites W2097833793 @default.
- W1647103339 cites W2100019646 @default.
- W1647103339 cites W2103317919 @default.
- W1647103339 cites W2112459589 @default.
- W1647103339 cites W2113660296 @default.
- W1647103339 cites W2117181435 @default.
- W1647103339 cites W2117320004 @default.
- W1647103339 cites W2118341398 @default.
- W1647103339 cites W2118431434 @default.
- W1647103339 cites W2119085032 @default.
- W1647103339 cites W2121001711 @default.
- W1647103339 cites W2121739482 @default.
- W1647103339 cites W2122049982 @default.
- W1647103339 cites W2126040767 @default.
- W1647103339 cites W2128282420 @default.
- W1647103339 cites W2129278597 @default.
- W1647103339 cites W2129345992 @default.
- W1647103339 cites W2131129639 @default.
- W1647103339 cites W2132185316 @default.
- W1647103339 cites W2133996557 @default.
- W1647103339 cites W2134296086 @default.
- W1647103339 cites W2136310957 @default.
- W1647103339 cites W2136898254 @default.
- W1647103339 cites W2138662592 @default.
- W1647103339 cites W2143150127 @default.
- W1647103339 cites W2147378257 @default.
- W1647103339 cites W2149143260 @default.
- W1647103339 cites W2150115633 @default.
- W1647103339 cites W2150174204 @default.